#CVSS 9.6
All CosmicBytez Labs articles tagged #CVSS 9.6, across news, security advisories, how-to guides, and projects.
- Security
CVE-2026-11807: Critical Authorization Bypass in Event-Driven Ansible WebSocket API
A missing authorization flaw (CVSS 9.6) in Red Hat's Event-Driven Ansible allows any authenticated user to forge WebSocket messages and access plaintext...
- Security
CVE-2026-53470: migration-planner IDOR Exposes Cross-Tenant S3 Pre-Signed URLs
A critical improper access control vulnerability (CVSS 9.6) in Red Hat's migration-planner allows an authenticated attacker to bypass ownership checks and...
- Security
CVE-2026-53471: migration-planner JWT Source ID Claim Not Validated in Agent API
A critical improper authentication vulnerability (CVSS 9.6) in Red Hat's migration-planner agent-API middleware allows authenticated agents to update...
- Security
CVE-2026-2611: MLflow 3.9.0 Improper Origin Validation
A critical CVSS 9.6 vulnerability in MLflow 3.9.0 allows a remote attacker to exploit improper origin validation in the MLflow Assistant's /ajax-api...
- Security
CVE-2026-24303: Microsoft Partner Center Privilege
A critical privilege escalation vulnerability in Microsoft Partner Center allows an authorized attacker to elevate their privileges over a network,...