NEWSkillSec — elevating AI Skills security from malware detection to capability auditingSkillSecLearn more →
← Back to Intel Center
SECURITY INTEL · DAILY
RSS

2026-10-01 ~ 10-07 Daily Security Intelligence

CSSA Exclusive Early Warning 2

CSSA Exclusive Early Warning 9.1 Critical

Missing Nacos authentication plugin silently bypasses authorization, allowing unauthorized access to sensitive APIs

When the authentication plugin configured by nacos.core.auth.system.type is absent from the classpath, AbstractProtocolAuthService.enableAuth returns false, causing the authentication filter to silently allow requests. An attacker can directly call APIs protected by the @Secured annotation without any credentials. This flaw leaves the system without access control even though authentication appears to be enabled, exposing sensitive data and allowing unauthorized execution of business logic.

Component
Nacos is Alibaba's open-source, cloud-native platform for dynamic service discovery, configuration management, and service management. Its core architecture includes server and client modules that provide efficient service registration, health checks, and configuration delivery in microservice environments. Centralized governance reduces coupling in distributed systems and improves operations automation.
Type
Not Failing Securely ('Failing Open') (CWE-636)
Repo
Remediation
  • Change the code so that all requests are denied by default if the authentication plugin fails to load or is misconfigured, or validate the configuration strictly at startup and prevent the service from running. Remove the unsafe fallback that only logs a warning without blocking traffic.
CSSA Exclusive Early Warning 10.0 Critical

Relay workflow dispatch handles untrusted code references, compromising confidentiality and integrity

An attacker can exploit a flaw introduced by PR #1665 to select a malicious branch reference through a `workflow_dispatch` event, replacing the default validation logic. Because the checked-out code directly contains executable scripts and the source reference is not required to be immutable, the attacker can remove the built-in identity allowlist and inject malicious workflow code. The vulnerability gives the attacker access to privileged credentials in the `snapshot-qualification` environment, exposing Daytona and cross-repository keys and severely compromising the system's confidentiality and integrity.

Component
Relay is the core coordination component of the AgentWorkforce open-source project, managing qualification workflows and resource scheduling. Its architecture is deeply integrated with GitHub Actions to automate validators, installation scripts, and cleanup tasks. It acts as a trust-boundary controller within the system, processing code submissions from external candidate branches and running sensitive operations in protected environments to support model providers and fleet orchestration across multiple clouds.
Type
Inclusion of Functionality from Untrusted Control Sphere (CWE-829)
Repo
Remediation
  • Strictly separate executable workflow code from candidate data sources, and load sensitive operations only from the trusted main branch. Implement validation based on artifact digests, restrict permissions associated with environment variables, and prohibit dynamic references to unverified external code paths.

CVE Intelligence 3

CVE-2026-74864 CVSS 10.0 Critical 2026-09-30

SOGo x-webobjects-remote-user identity spoofing vulnerability allows unauthorized access

In SOGo versions before 5.8.0~ynh9, flawed authorization logic in the configuration module allows authorization bypass through a user-controlled key (CWE-639). Nginx does not strip the HTTP header "x-webobjects-remote-user", and the SOGo configuration unconditionally trusts that header without verifying a password. Any client can therefore supply the header to gain access as any user, including privileged users, without providing a password. The vulnerability affects all SOGo users who have not updated to 5.8.0~ynh9, particularly deployments using YunoHost. An attacker only needs to craft a request containing the specific HTTP header to exploit the vulnerability remotely, with no user interaction.

Component
SOGo is an open-source enterprise collaboration suite providing calendar, contact, and email services. It is often used with reverse proxies such as Nginx.
Risks
  • From ordinary user to administrator: An attacker who spoofs a privileged user's identity can directly obtain administrator privileges
  • Complete system control: An attacker can exploit the vulnerability to log in as any user and view, modify, or delete data or perform administrative operations
  • No-user-interaction attack: By crafting a malicious HTTP request, an attacker can directly obtain session privileges without any interaction from the victim
Source
Remediation
  • Immediately upgrade SOGo to 5.8.0~ynh9 or later
  • Explicitly strip or ignore the "x-webobjects-remote-user" header in the Nginx configuration
  • Enable strict authentication and avoid relying on a single HTTP header for authorization decisions
CVE-2026-96349 CVSS 10.0 Critical 2026-09-30

SiteSkite unauthenticated remote code execution vulnerability allows complete system control

In SiteSkite 2.1.8 and earlier, the core processing module contains an unauthenticated remote code execution (RCE) flaw. Improper control of code generation (CWE-94) allows an attacker to send crafted requests over the network and directly trigger code injection without authentication. The vulnerability allows arbitrary system commands to run on the target server, resulting in data disclosure, loss of integrity, and service unavailability. All SiteSkite versions <= 2.1.8 are affected, and public proof-of-concept (PoC) exploit code is already available. An attacker only needs network access to control the server remotely, with no user interaction.

Component
SiteSkite is an open-source software component commonly used for website building or content management, supporting dynamic content generation and interactive features.
Risks
  • Complete system control: An attacker can execute arbitrary code on the victim system and, depending on user privileges, install programs, view, modify, or delete data, or create new accounts with full privileges
  • No-user-interaction attack: An attacker does not need to induce clicks or input; sending a malicious request over the network is enough to trigger remote code execution
  • Severe impact: The CVSS score of 10.0 indicates serious damage to confidentiality, integrity, and availability, with low attack complexity and very easy exploitation
Source
Remediation
  • Immediately upgrade SiteSkite to 2.1.9 or later to fix the vulnerability
  • Configure rules in the Web application firewall (WAF) to block malicious code injection requests targeting this component
  • Restrict network access to SiteSkite-related ports, allowing connections only from trusted IP addresses
CVE-2026-102490 CVSS 10.0 Critical 2026-10-01

Zammad local privilege escalation vulnerability allows a local user to gain root privileges

All versions of Zammad, including the latest alpha version, contain a severe security flaw that allows the local zammad user to escalate privileges to root. Missing or misconfigured privilege controls allow an attacker with zammad user privileges to bypass system restrictions and perform privileged operations. Successful exploitation gives the attacker the highest level of system control, allowing a complete server takeover. The vulnerability affects all unpatched Zammad deployments, regardless of version. Exploitation requires local zammad user privileges. However, because Zammad usually runs as a service, a compromised service or another entry point can make this vulnerability a key stepping stone for lateral movement and privilege escalation.

Component
Zammad is an open-source, Web-based ticketing system for customer support and help desk management, with multichannel integration.
Risks
  • From ordinary user to administrator: The local zammad user can exploit the vulnerability to escalate directly to root and gain the highest level of system control
  • Complete system control: An attacker can use root privileges to execute arbitrary code on the server, install backdoors, steal sensitive data, modify system configuration, or disrupt service availability
  • Local privilege escalation: Although initial local access is required, the vulnerability greatly lowers the attack barrier, allowing anyone who obtains zammad user privileges to take complete control of the host
Source
Remediation
  • Immediately review and restrict the zammad user's system privileges according to the principle of least privilege
  • Monitor system call logs for zammad processes to detect abnormal privilege escalation
  • Watch for official security patches promptly or upgrade to a fixed version; if no patch is available, consider isolating the runtime environment

Package Poisoning 15

Package Poisoning npm 2026-10-02

kartykgithub-ph-b@1.0.0 flagged as malicious

The component was found to communicate with a domain associated with malicious activity and execute one or more commands associated with malicious behavior.

MD5
408b640877c3e9c3f27b08e6a59403e7
Package Poisoning npm 2026-10-02

kartykgithub-ph-e@1.0.0 flagged as malicious

The component was found to communicate with a domain associated with malicious activity and execute one or more commands associated with malicious behavior.

MD5
9aedda80527e93b7348d6abf994c1543
Package Poisoning npm 2026-10-02

kartykgithub-ph-f@1.0.0 flagged as malicious

The component was found to communicate with a domain associated with malicious activity and execute one or more commands associated with malicious behavior.

MD5
bdd3e8662838f423322479982ec6dcdd
Package Poisoning npm 2026-10-05

css-interop-observer-polyfill@1.0.0 flagged as malicious

The component was found to communicate with a domain associated with malicious activity and execute one or more commands associated with malicious behavior.

MD5
734bf6a15b4741937b0a3884965df29e
Package Poisoning npm 2026-10-05

css-relative-color-util@1.0.0 flagged as malicious

The component was found to communicate with a domain associated with malicious activity and execute one or more commands associated with malicious behavior.

MD5
4bf16747e00dccef4dd0913ca0dbd2da
Package Poisoning npm 2026-10-05

css-scroll-anchor-polyfill@1.0.0 flagged as malicious

The component was found to communicate with a domain associated with malicious activity and execute one or more commands associated with malicious behavior.

MD5
6c28686c7098bd576cddabe1022400bb
Package Poisoning npm 2026-10-05

focus-visible-polyfill-lite@1.0.0 flagged as malicious

The component was found to communicate with a domain associated with malicious activity and execute one or more commands associated with malicious behavior.

MD5
f7eb4ad055654131ebd7473019ca01d4
Package Poisoning npm 2026-10-05

@kibt/www-nuxt-i18n@99.0.1 flagged as malicious

The component was found to communicate with a domain associated with malicious activity and execute one or more commands associated with malicious behavior.

MD5
ef4c5fc05701c4b4f9ebb267e8779c10
Package Poisoning npm 2026-10-05

tiny-focusgroup-helper@1.0.0 flagged as malicious

The component was found to communicate with a domain associated with malicious activity and execute one or more commands associated with malicious behavior.

MD5
e7aadb02e68161e102089d9fea652bf1
Package Poisoning npm 2026-10-05

ultimate-websocket@1.0.0 flagged as malicious

The component was found to bypass the npm registry to download and execute attacker-controlled code directly from an insecure GitHub URL. Its postinstall script loads and runs the malicious module during installation.

MD5
74afcc1ca8dc7ebd0af7f34adf9f32b2
Package Poisoning npm 2026-10-05

@inpeek/odata@99.99.99 flagged as malicious

The component was found to communicate with a domain associated with malicious activity and execute one or more commands associated with malicious behavior.

MD5
a221a8aed09a5c960f20bae1576dc28f
Package Poisoning npm 2026-10-05

risk-detection@99.9.1 flagged as malicious

The component was found to communicate with a domain associated with malicious activity and execute one or more commands associated with malicious behavior.

MD5
f729b5affa6da691571374b5d43ba912
Package Poisoning npm 2026-10-06

serpacksven@>= 0 flagged as malicious

Any computer on which this package has been installed or run should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from another computer. Remove the package, but because full control of the computer may already have been handed to an outside entity, removing the package cannot be guaranteed to eliminate all malware introduced by its installation.

MD5
6ed15814f63f825b33ecfc10bf40da91
Package Poisoning npm 2026-10-06

serpacksven1@>= 0 flagged as malicious

The component was found to communicate with a domain associated with malicious activity and execute one or more commands associated with malicious behavior.

MD5
4a3e53d0e7e57c6fb9c61060503da116
Package Poisoning npm 2026-10-06

serpacksven2@>= 0 flagged as malicious

The component was found to contain malicious code. Any computer on which this package has been installed or run should be considered fully compromised, and all keys and credentials stored on that computer should be rotated immediately from another computer.

MD5
b640de1f3402c60ad865e2c39625a1ac