CVE-2026-1918
published 2026-07-28CVE-2026-1918: IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.0.0 through…
PriorityP426medium4.9CVSS 3.1
AVNACLPRHUINSUCHINAN
EPSS
0.40%
31.4th percentile
IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 stores potentially sensitive information in log files that could be read by a privileged user.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | sterling_b2b_integrator | 6.2.0.0 – 6.2.0.5_2 | — |
| ibm | sterling_b2b_integrator | 6.2.1.0 – 6.2.1.1_2 | — |
| ibm | sterling_b2b_integrator | 6.2.2.0 – 6.2.2.0_1 | — |
| ibm | sterling_file_gateway | 6.2.0.0 – 6.2.0.5_2 | — |
| ibm | sterling_file_gateway | 6.2.1.0 – 6.2.1.1_2 | — |
| ibm | sterling_file_gateway | 6.2.2.0 – 6.2.2.0_1 | — |
| processwire | processwire | 0 – 3.0.255 | — |
CVSS provenance
nvdv3.14.9MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
vendor_redhat3.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and
ghsa_unreviewed·2026-07-28
CVE-2026-1918 [MEDIUM] CWE-532 IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and
IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 stores potentially sensitive information in log files that could be read by a privileged user.
VulDB
IBM Sterling B2B Integrator/Sterling File Gateway up to 6.2.0.5_2/6.2.1.1_2/6.2.2.0_1 log file
vuldb·2026-07-28·CVSS 4.9
CVE-2026-1918 [MEDIUM] IBM Sterling B2B Integrator/Sterling File Gateway up to 6.2.0.5_2/6.2.1.1_2/6.2.2.0_1 log file
A vulnerability marked as problematic has been reported in IBM Sterling B2B Integrator and Sterling File Gateway up to 6.2.0.5_2/6.2.1.1_2/6.2.2.0_1. Affected by this issue is some unknown functionality. This manipulation causes sensitive information in log files.
The identification of this vulnerability is CVE-2026-1918. It is possible to initiate the attack remotely. There is no exploit available.
GHSA
NocoDB: Server-Side Request Forgery via Base Migration URL
ghsa·2026-06-17
CVE-2026-53930 [MEDIUM] CWE-918 NocoDB: Server-Side Request Forgery via Base Migration URL
NocoDB: Server-Side Request Forgery via Base Migration URL
### Summary
The base-migration endpoint accepted a caller-supplied URL that the migration worker
dereferenced without enforcing protocol or destination, allowing scheme abuse
(`file:`, `ftp:`, etc.) and probing of internal HTTP destinations.
### Details
The `migrate` endpoint is restricted to the workspace owner role by ACL. The remaining
gaps were (a) protocol validation — the controller now parses `body.migrationUrl` as a
`URL` and rejects anything whose protocol is not `http:` or `https:` — and (b) private
destination filtering — the worker already runs through `useAgent(targetUrl)` from
`request-filtering-agent`, which blocks RFC 1918, loopback, and link-local at the
socket layer.
### Impact
With the workspace owner role, a
GHSA
Budibase: Unvalidated VectorDB Host Parameter Enables SSRF
ghsa·2026-06-12
CVE-2026-48148 [MEDIUM] CWE-918 Budibase: Unvalidated VectorDB Host Parameter Enables SSRF
Budibase: Unvalidated VectorDB Host Parameter Enables SSRF
### Summary
The VectorDB configuration endpoint in Budibase accepts a host parameter that undergoes no validation against internal IP ranges, reserved hostnames, or URL schemes. Any authenticated user with builder-level access can supply an arbitrary host value such as `169.254.169.254` or localhost, causing the server to initiate outbound TCP connections to internal network addresses or cloud metadata endpoints on their behalf.
### Details
The validator responsible for VectorDB creation and updates defines the host field as `Joi.string().required()`, which enforces only that the value is a non-empty string. No allowlist of external hostnames, no blocklist of RFC 1918 or link-local ranges, and no scheme validation are applied b
GHSA
ProcessWire: server-side request forgery vulnerability in the admin panel's 'Add Module From URL' feature
ghsa·2026-04-16
CVE-2026-40500 [MEDIUM] CWE-918 ProcessWire: server-side request forgery vulnerability in the admin panel's 'Add Module From URL' feature
ProcessWire: server-side request forgery vulnerability in the admin panel's 'Add Module From URL' feature
ProcessWire CMS version 3.0.255 and prior contain a server-side request forgery vulnerability in the admin panel's 'Add Module From URL' feature that allows authenticated administrators to supply arbitrary URLs to the module download parameter, causing the server to issue outbound HTTP requests to attacker-controlled internal or external hosts. Attackers can exploit differentiable error messages returned by the server to perform reliable internal network port scanning, host enumeration across RFC-1918 ranges, and potential access to cloud instance metadata endpoints.
Red Hat
unbound: Unbound: Information disclosure due to local policy bypass via unbound-control
vendor_redhat·2026-07-22·CVSS 3.1
CVE-2026-55708 [LOW] CWE-213 unbound: Unbound: Information disclosure due to local policy bypass via unbound-control
unbound: Unbound: Information disclosure due to local policy bypass via unbound-control
In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, the 'view_local_data' and 'view_local_datas' commands of 'unbound-control' create a bare local zones tree for an already configured named view when the view is configured with no local data to begin with. However, the creation through the control interface omits adding the default-protected zones (e.g., RFC 1918 reverse, AS112 zones, .onion, .localhost). Once the local zone tree exists without the defaults, every query for a default-protected name from a client mapped to that view escapes to the public DNS via the iterator instead of being answered locally, bypassing local policy expectations.
A flaw in Unbound's unbound-control utility can omit
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-28
Published