NEWSkillSec — elevating AI Skills security from malware detection to capability auditingSkillSecLearn more →
← Back to Intel Center
SECURITY INTEL · DAILY
Link copied RSS

2026-09-15 Daily Security Intelligence

8 itemsTop severity 10.0 (Critical)CSSA 2 · CVE 2 · Poisoning 4

CSSA Exclusive Early Warning 2

CSSA Exclusive Early Warning 10.0 Critical

Aim tracking server permanently deletes experiment data at arbitrary paths due to missing authorization checks

An attacker exploits the lack of allowlist validation on remote method calls by sending a crafted HTTP request over the network to the default open port, directly triggering server-side getattr to dynamically execute an arbitrary function, then invoking the Repo.rm method to run shutil.rmtree. The behavior is not confined to the mounted directory and requires no authentication, forcing recursive deletion of .Aim metadata directories under any writable path on the server and destroying experiment-data integrity and service availability.

Component
Aim is an experiment tracking and management tool for machine-learning engineers. Its core component runs as a backend service and is designed to receive client commands through RESTful API endpoints, persist model-training metrics, parameters and metadata, and support structured queries. The system architecture relies on a remote-procedure-call mechanism to support data collection and visual analysis in distributed environments.
Type
Missing Authorization (CWE-862)
Repo
Remediation
  • Fix the code logic so that method_name is strictly allowlist-filtered at the dispatch layer, forbid dangerous operations such as rm, enable strong authentication on all API endpoints, and confine file operations to a predefined sandbox or mounted directory so that resource access follows the principle of least privilege.
CSSA Exclusive Early Warning 10.0 Critical

AiToEarn component uses hard-coded credentials leading to authentication bypass and administrator privilege escalation

An attacker exploits static default AUTH_SECRET and internalToken values in the code and, with no preconditions, can craft a forged JWT token or send the known internal token as a Bearer header. Because the system does not invalidate default configuration and directly trusts the isManager claim in the token or the static token value, the attacker can bypass the normal authentication flow, illegally obtain administrator privileges or access protected internal-service endpoints.

Component
AiToEarn is an Electron-based application whose core backend service relies on a JWT mechanism for authentication and authorization. It aims to maintain user sessions, apply role-based authorization and secure communication among internal microservices through standardized API endpoints, ensuring orderly execution of business logic and integrity of data exchange.
Type
Use of Hard-coded Credentials (CWE-798)
Repo
Remediation
  • Remove all hard-coded credentials from source code, require dynamically generated strong random keys at deployment time, implement a fail-safe policy that refuses to start instances using default values, and introduce an independent internal-service authentication mechanism to replace static token checks.

CVE Intelligence 2

CVE-2026-82232 CVSS 10.0 Critical 2026-09-14

Apache Syncope SQL injection vulnerability leading to arbitrary SQL execution

In Apache Syncope versions before 3.0.16, 4.0.7 and 4.1.2, the Task search feature does not correctly sanitize sort clauses, resulting in an SQL injection (CWE-89) security defect. An administrator with appropriate privileges can craft a malicious sort parameter containing stacked queries and execute arbitrary SQL statements, threatening database integrity and system security. Apache Syncope has a logic defect when handling Task search requests; an attacker can trigger it with a crafted API request, leading to complete database control or sensitive-data disclosure. The vulnerability affects all Apache Syncope users who have not updated to 4.0.8 or 4.1.3, including enterprise identity-management deployments. The attacker must have administrator privileges, but successful exploitation can completely take over the backend database.

Component
Apache Syncope is an open-source enterprise identity and access management (IAM) platform that provides user-lifecycle management, access control and multi-source identity synchronization.
Risks
  • Complete database control: An attacker can use this vulnerability to execute arbitrary SQL commands, including reading, modifying or deleting sensitive identity information in the database
  • Privilege escalation and persistence: An attacker can change administrator passwords or create high-privilege accounts and thereby control the identity-management system long term
  • Data disclosure: SQL injection can extract user credentials, personally identifiable information (PII) and other confidential data
Source
Remediation
  • Immediately upgrade Apache Syncope to 4.0.8 or 4.1.3 or later
  • Restrict access to the Task search API and enforce strict network isolation
  • Monitor database logs for anomalous stacked queries or high-frequency SQL execution
CVE-2026-86460 CVSS 10.0 Critical 2026-09-14

Apache Syncope Cypher injection vulnerability leading to remote code execution

In Apache Syncope versions before 3.0.16, 4.0.7 and 4.1.2, the Neo4j persistence layer does not sufficiently escape input when handling certain FIQL search conditions, resulting in a Cypher injection vulnerability (CWE-89). An attacker can craft a malicious FIQL search parameter and inject arbitrary Cypher queries, thereby bypassing authentication, stealing sensitive data or modifying database contents. The vulnerability affects Apache Syncope 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7 and 4.1.0-M0 through 4.1.2. An attacker needs no complex preconditions and can trigger it by sending a crafted request to a vulnerable endpoint, which may lead to data disclosure, integrity compromise or even remote code execution.

Component
Apache Syncope is an open-source identity and access management (IAM) platform used to centrally manage user identities, permissions and authentication flows, and it supports multiple backend stores including the Neo4j graph database.
Risks
  • Data disclosure and tampering: An attacker can use the injection vulnerability to read, modify or delete sensitive identity information and permission configuration in the Neo4j database
  • Privilege escalation: By manipulating database records, an attacker may elevate their own account privileges and obtain administrator control
  • Remote code execution: Under certain configurations, a malicious Cypher query may trigger system-command execution and completely control the server
  • Unauthenticated attack: If the search endpoint does not strictly restrict access, an attacker can launch the attack directly from an external network
Source
Remediation
  • Immediately upgrade Apache Syncope to 4.0.8 or 4.1.3 or later
  • Enforce strict input validation and filtering on the FIQL search endpoint
  • Restrict Neo4j database access so that only the application server connects with least privilege
  • Deploy a web application firewall (WAF) to intercept anomalous Cypher-injection signatures

Package Poisoning 4

Package Poisoning npm 2026-09-15

ultra-ws@1.0.0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
032019b47e16291e2cc0c273f81c444d
Package Poisoning npm 2026-09-15

get-power@1.0.3 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
bbe773232bc99dd1085bc38910215e22
Package Poisoning npm 2026-09-15

n8n-nodes-sysdiag2@2.0.0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
b8c56576d69cd002a7198b0545ea447c
Package Poisoning npm 2026-09-15

@yggbrasil/api@>= 0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
619a66eff2b9a267c8c1f1c7030656a6