Vulnerabilities in aehrc
6 resultsVexday analysis
A AEHRC apresenta 6 vulnerabilidades catalogadas, todas publicadas nos últimos 90 dias, indicando risco emergente. Nenhuma está sob ataque ativo (KEV) ou classificada como crítica, mas a concentração em CWE-918 (Server-Side Request Forgery) aponta fraqueza específica em validação de requisições que merece atenção na avaliação de risco atual.
CVE-2026-47661HIGHPathling has path traversal in $result endpoint that allows arbitrary warehouse file readEPSS 0.5%CVE-2026-47659HIGHPathling has path traversal in $import-pnp manifest that enables read-capable SSRF via /jobs/{jobId}/{filename}EPSS 0.5%CVE-2026-47660HIGHPathling: Explicit oauthMetadataUrl in bulk-submit allows OAuth client credential exfiltrationEPSS 0.3%CVE-2026-47662HIGHPathling $bulk-submit allows bearer-token exfiltration and persistent warehouse poisoning via unvalidated manifest output URLsEPSS 0.3%CVE-2026-47663HIGHPathling: Typed CRUD/search/batch providers can lead to server-wide PHI exfiltration and cross-resource mutationEPSS 0.2%CVE-2026-47664HIGHPathling: $import-pnp operation enables authenticated SSRF, credential leakage, and warehouse data poisoningEPSS 0.2%