CVE-2026-19572Critical· 9.3▾ MidnightA security vulnerability has been identified in FlexNet Publisher lmadmin. The vulnerability exists in a SOAP handler, where a hardcoded authentication bypass could allow an unauthenticated user to obtain a privileged administrator sessi…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 51.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A security vulnerability has been identified in FlexNet Publisher lmadmin. The vulnerability exists in a SOAP handler, where a hardcoded authentication bypass could allow an unauthenticated user to obtain a privileged administrator session without providing valid credentials.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-39769High· 7.5Unauthenticated Broken Authentication in Graphina <= 3.1.12 versions.
CVE-2026-39793High· 8.8Subscriber Broken Authentication in Simple JWT Login 4.0.0 versions.
CVE-2026-100518Medium· 5.3Unauthenticated Broken Authentication in Advanced Google reCAPTCHA <= 5.40 versions.
CVE-2026-100261Medium· 5.4In JetBrains YouTrack before 2026.2.18991 changing article visibility settings was possible without update permission
CVE-2026-88828Medium· 5.4The Blacklist Manager for WooCommerce WordPress plugin from 1.3.0 to 2.3.1 does not enforce its user blocking on every authentication path, allowing the holder of an account the site owner has blocked to keep authenticating with that acc…
CVE-2026-63493High· 8.1Snipe-IT is an IT asset/license management system