#Unauthenticated Access
All CosmicBytez Labs articles tagged #Unauthenticated Access, across news, security advisories, how-to guides, and projects.
- Security
CVE-2026-57123: PraisonAI MCP Server Exposes Unauthenticated Tool Access
PraisonAI's MCP tools server binds to 0.0.0.0 with no auth or origin checks, letting any reachable client invoke shell and file tools.
- Security
CVE-2026-11841: AppEngine Fileaccess Unauthenticated Filesystem R/W (CVSS 9.4)
A critical vulnerability in AppEngine's HTTP-based file access feature exposes sensitive filesystem directories to unauthenticated read and write...
- Security
CVE-2026-42569: phpVMS Critical Unauthenticated Legacy
A critical vulnerability (CVSS 9.4) in phpVMS before version 7.0.6 allows unauthenticated attackers to access a legacy import feature, potentially...
- Security
CVE-2026-28766: Gardyn Smart Garden API Exposes All User
A critical unauthenticated information disclosure vulnerability in the Gardyn smart garden platform exposes all registered user account information via a...
- Security
CVE-2026-34162: FastGPT Unauthenticated HTTP Proxy Enables
A maximum-severity vulnerability in FastGPT AI agent platform exposes an unauthenticated HTTP proxy testing endpoint that accepts arbitrary user-supplied...