Batch #6 - August 2026 (7 advisories · 4 critical · 4 unauth)
·
3 commits
to main
since this release
Batch #6 — August 2026
7 advisories · 7 vendors · every advisory ships a full root-cause analysis + a working, reproducible PoC.
Sixth batch — expanding coverage into data-science notebooks, document generation, fax servers, task automation, ITSM, IT monitoring, and video surveillance. Headline: JetBrains Datalore On-Premises unauthenticated RCE via an interactive-report access-mapping flaw. Full writeups on https://0day-rubbish.com/blog; PoC code under product/<vendor>/<version>/<type>/exploit/.
| # | Product | Affected Version | CVSS | Class | Advisory & PoC |
|---|---|---|---|---|---|
| 1 | JetBrains Datalore On-Premises | 2026.2.3 | 9.8 | Unauth RCE via InteractiveReport access-mapping flaw | InteractiveReport READ→EXECUTE → Unauth RCE |
| 2 | Docmosis Tornado | 2.11.3 | 9.8 | Unauth Arbitrary File Write → cron (Root) | storeTo=file: → Root RCE |
| 3 | ActFax | 10.70 | 9.8 | Unauth LPD Ghostscript %pipe% (SYSTEM) | LPD %pipe% → SYSTEM RCE |
| 4 | RoboTask | 11.0.5.1229 | 9.8 | Unauth REST API Task Execution | REST API Unauth → Task RCE |
| 5 | Countersoft Gemini | 7.3.0 | 8.8 | Auth SQLi → xp_cmdshell (SYSTEM-able) | SQLi → xp_cmdshell RCE |
| 6 | Veeam ONE Reporter | 13.1 | 8.8 | Auth Command Injection → Local Admin | CommandExecutor → Local Admin RCE |
| 7 | Wavestore VMS | 6.48.809 | 8.8 | Auth Cmd Injection → Root | venusd /simple/export → Root RCE |
Highlights
- 4 critical (CVSS ≥ 9.0) · 4 unauthenticated · 3 authenticated (deep-chain)
- Headline: JetBrains Datalore On-Premises — anonymous attacker reaches an EXECUTE-gated RPC through a public interactive report (shipped
ALLOW_ANONYMOUS_RPC_ACCESS=true+ READ→EXECUTE mapping flaw), executes arbitrary code in the agent container via unsanitized pip install. - Other unauth entries: Docmosis Tornado arbitrary file write → root cron RCE; ActFax LPD Ghostscript
%pipe%SYSTEM RCE; RoboTask REST API unauthenticated task execution. - Authenticated deep-chain entries: Countersoft Gemini SQLi → xp_cmdshell; Veeam ONE Reporter CommandExecutor → local admin; Wavestore VMS
/simple/exportcommand injection → root. - Attack classes: access-control mapping, arbitrary file write, Ghostscript %pipe%, missing authentication, SQL injection, command injection, unsanitized command execution.
Totals
7 advisories · 7 vendors · 4 unauthenticated · 3 authenticated (deep-chain) · 6 root/SYSTEM · all with reproducible PoC.
Cumulative across 6 batches: 58 advisories.