Vulnerabilities
Vulnerable Software
Security Vulnerabilities
XenForo before 2.3.13 contains an authentication bypass vulnerability in the OAuth2 token endpoint that allows unauthenticated attackers to obtain valid token pairs by submitting empty values for client_secret and code_verifier parameters. Attackers can exploit PHP truthy evaluation logic, which treats empty strings as false and skips client secret validation and PKCE code verifier validation, to exchange a valid authorization code for a token pair without proving client identity or holding the PKCE commitment.
CVSS Score
9.1
EPSS Score
0.005
Published
2026-09-08
CommServe contained an authentication bypass issue affecting access authorization and information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe.
CVSS Score
8.7
EPSS Score
0.003
Published
2026-09-08
CommServe contained a path traversal issue affecting information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe.
CVSS Score
8.3
EPSS Score
0.004
Published
2026-09-08
CommServe contained a cryptographic signature verification issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update CommServe and Web Server.
CVSS Score
8.7
EPSS Score
0.002
Published
2026-09-08
Cvlaunchd contained a missing authorization issue affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X.
CVSS Score
7.7
EPSS Score
0.003
Published
2026-09-08
Command Center API contained an authentication bypass issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Command Center.
CVSS Score
9.3
EPSS Score
0.003
Published
2026-09-08
DataCube contained a path traversal issue affecting security feature enforcement. Software customers upgrade to resolved maintenance release. Update Content Extractor and Index Store.
CVSS Score
8.5
EPSS Score
0.001
Published
2026-09-08
Content Extractor contained a deserialization of untrusted data issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Content Extractor.
CVSS Score
7.3
EPSS Score
0.002
Published
2026-09-08
Private Metrics Server contained a missing authentication condition affecting metrics upload functionality and service availability. Software customers upgrade to resolved maintenance release. Update Private Metrics Server.
CVSS Score
8.8
EPSS Score
0.003
Published
2026-09-08
Private Metrics Server contained an SQL injection condition affecting database operations. Software customers upgrade to resolved maintenance release. Update Private Metrics Server.
CVSS Score
8.8
EPSS Score
0.003
Published
2026-09-08


Contact Us

Shodan ® - All rights reserved