CVE-2026-57501None· 0.0▾ SunlitZen is a firefox-based browser. Prior to 1.21.5b, Zen's glance and split-view context-menu actions, Open link in glance and Split link in new tab, load a page-controlled link URL with the System principal instead of the originating page'…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 11.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
0.3% → 0.5%
Zen is a firefox-based browser. Prior to 1.21.5b, Zen's glance and split-view context-menu actions, Open link in glance and Split link in new tab, load a page-controlled link URL with the System principal instead of the originating page's principal, allowing a malicious web page to place a link to a file URL that can load with System privileges when opened through either context-menu item and bypass the content-to-file security check that blocks an ordinary click. This issue is fixed in version 1.21.5b.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-11861Critical· 9.6Freeipa: idm: ipa: freeipa: obtaining tgs with impersonating cname through trust relationships
CVE-2026-96881Medium· 5.3A vulnerability was determined in TaleLin lin-cms-spring-boot up to 0.2.1
CVE-2026-96882Medium· 5.3A vulnerability was identified in TaleLin lin-cms-spring-boot up to 0.2.1
CVE-2026-96880Medium· 5.3A vulnerability was found in TaleLin lin-cms-spring-boot up to 0.2.1
CVE-2026-96763Medium· 5.4A security flaw has been discovered in kvcache-ai mooncake up to 0.3.12/0.3.13.post1/0.3.14-rc1
CVE-2026-86583High· 8.8The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.4.17 via the plugin's own export and re-import workflow