Skip to content

Batch #6 - August 2026 (7 advisories · 4 critical · 4 unauth)

Choose a tag to compare

@Exploit-Garbage Exploit-Garbage released this 18 Aug 05:11
· 3 commits to main since this release

Batch #6 — August 2026

7 advisories · 7 vendors · every advisory ships a full root-cause analysis + a working, reproducible PoC.

Sixth batch — expanding coverage into data-science notebooks, document generation, fax servers, task automation, ITSM, IT monitoring, and video surveillance. Headline: JetBrains Datalore On-Premises unauthenticated RCE via an interactive-report access-mapping flaw. Full writeups on https://0day-rubbish.com/blog; PoC code under product/<vendor>/<version>/<type>/exploit/.

# Product Affected Version CVSS Class Advisory & PoC
1 JetBrains Datalore On-Premises 2026.2.3 9.8 Unauth RCE via InteractiveReport access-mapping flaw InteractiveReport READ→EXECUTE → Unauth RCE
2 Docmosis Tornado 2.11.3 9.8 Unauth Arbitrary File Write → cron (Root) storeTo=file: → Root RCE
3 ActFax 10.70 9.8 Unauth LPD Ghostscript %pipe% (SYSTEM) LPD %pipe% → SYSTEM RCE
4 RoboTask 11.0.5.1229 9.8 Unauth REST API Task Execution REST API Unauth → Task RCE
5 Countersoft Gemini 7.3.0 8.8 Auth SQLi → xp_cmdshell (SYSTEM-able) SQLi → xp_cmdshell RCE
6 Veeam ONE Reporter 13.1 8.8 Auth Command Injection → Local Admin CommandExecutor → Local Admin RCE
7 Wavestore VMS 6.48.809 8.8 Auth Cmd Injection → Root venusd /simple/export → Root RCE

Highlights

  • 4 critical (CVSS ≥ 9.0) · 4 unauthenticated · 3 authenticated (deep-chain)
  • Headline: JetBrains Datalore On-Premises — anonymous attacker reaches an EXECUTE-gated RPC through a public interactive report (shipped ALLOW_ANONYMOUS_RPC_ACCESS=true + READ→EXECUTE mapping flaw), executes arbitrary code in the agent container via unsanitized pip install.
  • Other unauth entries: Docmosis Tornado arbitrary file write → root cron RCE; ActFax LPD Ghostscript %pipe% SYSTEM RCE; RoboTask REST API unauthenticated task execution.
  • Authenticated deep-chain entries: Countersoft Gemini SQLi → xp_cmdshell; Veeam ONE Reporter CommandExecutor → local admin; Wavestore VMS /simple/export command injection → root.
  • Attack classes: access-control mapping, arbitrary file write, Ghostscript %pipe%, missing authentication, SQL injection, command injection, unsanitized command execution.

Totals

7 advisories · 7 vendors · 4 unauthenticated · 3 authenticated (deep-chain) · 6 root/SYSTEM · all with reproducible PoC.

Cumulative across 6 batches: 58 advisories.