CVE-2026-24359
published 2026-03-25CVE-2026-24359: Authentication Bypass Using an Alternate Path or Channel vulnerability in Dokan, Inc. Dokan dokan-lite allows Authentication Abuse.This issue affects Dokan…
PriorityP260high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.52%
41.5th percentile
Authentication Bypass Using an Alternate Path or Channel vulnerability in Dokan, Inc. Dokan dokan-lite allows Authentication Abuse.This issue affects Dokan: from n/a through <= 4.2.4.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| dokan_inc | dokan | <= 4.2.4 | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
ghsa8.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-24359 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.8
CVE-2026-24359 [CRITICAL] CVE-2026-24359 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-24359 :
WordPress vulnerability analysis and mitigation
Authentication Bypass Using an Alternate Path or Channel vulnerability in Dokan, Inc. Dokan dokan-lite allows Authentication Abuse.This issue affects Dokan: from n/a through <= 4.2.4.
Source : NVD
## 8.8
Score
Published March 25, 2026
Severity HIGH
CNA Score 8.8
Affected Technologies
WordPress
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 17.4
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
dokan-lite
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related WordPress vulnerabilities:
Bugzilla
CVE-2025-24359 python-asteval: ASTEVAL Vulnerable to Maliciously Crafted Format Strings Leading to Sandbox Escape [epel-all]
bugzilla·2025-01-24·CVSS 8.4
CVE-2025-24359 [HIGH] CVE-2025-24359 python-asteval: ASTEVAL Vulnerable to Maliciously Crafted Format Strings Leading to Sandbox Escape [epel-all]
CVE-2025-24359 python-asteval: ASTEVAL Vulnerable to Maliciously Crafted Format Strings Leading to Sandbox Escape [epel-all]
More information about this security flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2341976
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This package has changed maintainer in Fedora. Reassigning to the new maintainer of this component.
---
This package has changed maintainer in Fedora. Reassigning to the new maintainer of this component.
---
FEDORA-2026-79e569db98 (python-asteval-1.0.10-1.fc45) has been submitted as an update to Fedo
2026-03-25
Published