CVE-2026-12878High· 8.8▾ TwilightIn affected versions of the Codefresh platform an authenticated user can utilize an API endpoint to elevate to Admin permissions.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
In affected versions of the Codefresh platform an authenticated user can utilize an API endpoint to elevate to Admin permissions.
codefresh >= 2.0.0, < 2.11.15Upgrade past the affected range:
codefresh 2.11.15Connected by shared product, vendor, weakness, or advisory.
CVE-2018-16497High· 7.8In Versa Analytics, the cron jobs are used for scheduling tasks by executing commands at specific dates and times on the server
CVE-2021-20021Critical· 9.8A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.
CVE-2026-4881Medium· 6.5In affected versions of Octopus Server, permissions were not checked correctly resulting in any authenticated user being able to make server level changes using a certain API endpoint despite receiving an error.
CVE-2026-12269High· 8.8Zohocorp ManageEngine DDI Central 6.2.0 build below 6201 had a Keepalived configuration injection vulnerability in the HA configuration workflow
CVE-2026-18950High· 8.8A flaw was found in odh-dashboard
CVE-2026-101086Medium· 6.5Nezha Dashboard versions before 2.3.5 fail to restrict service monitor task types to supported probe types, allowing authenticated users with nezha:service:write scope to submit privileged task types through the service API