Database/Control plane, storage & DevOps

Lantronix EDS3000PS serial-to-Ethernet device server: Full bypass of the management-page login
Impact
Full bypass of the management-page login. Appending a specific suffix to a management URL, combined with a crafted Authorization header, gets an attacker straight into admin functionality with no valid credentials — including whatever serial console sessions the device is bridging.
Who can reach it
Purely network-based, no credentials required — the attacker just needs to reach the device's web management port and knows the URL/header trick published in the advisory.
What to do
Firmware flash to the fixed release; this is an auth-check logic bug, not something you can compensate for with a password change. Roll out per device; each flash briefly interrupts the serial bridging that device provides.
References
Related entries
- Palo Alto PAN-OS: GlobalProtect portal/gateway auth bypassCVE-2026-0257 · Palo Alto PAN-OSCritical
- Grafana MCP Server: caller-controlled X-Grafana-URL header turns grafana_api_request into a full SSRF primitiveCVE-2026-19516 · mcp-grafana (Grafana MCP Server, X-Grafana-URL destination control)Critical
- Apache CloudStack Proxmox extension (cross-tenant instance access): The extension keys CloudStack instances to ProxmoxCVE-2026-25199 · Apache CloudStack Proxmox extension (cross-tenant instance access)Critical
- BACnet Stack open-source C library (bacnet-stack) embedded in third-party controllers and gateways: A runCVE-2026-41475 · BACnet Stack open-source C library (bacnet-stack) embedded in third-party controllers and gatewaysCritical
- Ceph Monitor: any read-only CephX user can dump the config-key store, including cephadm's cluster-wide SSH keyCVE-2026-50152 · Ceph Monitor (MMonSubscribe config-key store authorization)Critical
- Apache Airflow FAB provider: Azure AD id_token issuer and audience unchecked, any tenant can log inCVE-2026-75156 · Apache Airflow FAB provider (Azure AD OAuth id_token issuer/audience validation)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.