Tag
#REST API
CVE-2026-67602: phpIPAM REST API Authentication Bypass Vulnerability
A critical vulnerability (CVE-2026-67602, CVSS 9.1) in phpIPAM before 1.8.2 allows unauthenticated attackers to bypass authentication and gain full API access, enabling them to read, write, and delete IP address management records. This vulnerability is due to an insecure object cache keying mechanism in the REST API.
CVE-2026-7327: Progress MarkLogic Server Improper Privilege Management Vulnerability
A high-severity vulnerability (CVSS 8.1) in Progress MarkLogic Server allows an authenticated user with administrative REST role to escalate privileges, potentially leading to unauthorized disclosure of sensitive server-side data. Affected versions include Progress MarkLogic Server before 11.3.6 and 12.0.3. Apply updates immediately.
Understanding and Defending Against CVE-2026-15291: Sensitive Information Exposure in Chat Help Plugin
The Chat Help – Click to Chat Button & Form plugin for WordPress is vulnerable to Sensitive Information Exposure due to missing authentication and authorization checks in its REST API endpoints. This allows unauthenticated attackers to extract sensitive data, including customer information and WordPress account credentials. The vulnerability has a CVSS score of 7.5 and affects all versions up to 3.1.3.