CVE-2026-102249High· 7.3▾ TwilightA security flaw has been discovered in REBUILD up to 4.4.11. This vulnerability affects unknown code of the file /commons/file-editor-save. The manipulation of the argument url/fileKey results in missing authorization. It is possible to …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 40.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A security flaw has been discovered in REBUILD up to 4.4.11. This vulnerability affects unknown code of the file /commons/file-editor-save. The manipulation of the argument url/fileKey results in missing authorization. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-102248High· 7.3A vulnerability was identified in Rebuild up to 4.4.7/4.5.0-beta5
CVE-2026-101139Low· 2.7A vulnerability was detected in Webkul Bagisto up to 2.4.6
CVE-2026-101000Critical· 10.0A vulnerability was determined in Netcore NBR100V2 1.3.240614.030928
CVE-2026-100879Medium· 4.3A security flaw has been discovered in zhistaredu StarTraining up to 3.8.1
CVE-2026-100744High· 7.3A flaw has been found in coollabsio Coolify up to 4.1.2
CVE-2025-13813Medium· 5.6A vulnerability was identified in moxi159753 Mogu Blog v2 up to 5.2