CVE-2026-43813
published 2026-07-27CVE-2026-43813: A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6…
PriorityP423medium6.5
A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. A maliciously crafted app may be able to bypass code signing enforcement.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_and_ipados | < 26.6 | 26.6 |
| apple | macos | < 26.6 | 26.6 |
| apple | tvos | < 26.6 | 26.6 |
| apple | visionos | < 26.6 | 26.6 |
| apple | watchos | < 26.6 | 26.6 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No advisories linked to this vulnerability.
Suricata
ET WEB_SPECIFIC_APPS GLPI Authenticated SQL Injection in Saved Searches (CVE-2023-43813)
suricata·2026-01-28·CVSS 6.5
CVE-2023-43813 [MEDIUM] ET WEB_SPECIFIC_APPS GLPI Authenticated SQL Injection in Saved Searches (CVE-2023-43813)
ET WEB_SPECIFIC_APPS GLPI Authenticated SQL Injection in Saved Searches (CVE-2023-43813)
Rule: alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS GLPI Authenticated SQL Injection in Saved Searches (CVE-2023-43813)"; flow:established,to_server; http.uri; content:"/ajax/pin_savedsearches.php"; fast_pattern; http.request_body; content:"itemtype|3d|"; pcre:"/^[^&]*?(?:[\x27\x22\x3b\x2d\x5c\x2a\x2f]|\x25(?:2[27aAdDfF]|3[bB]|5[cC]))/R"; http.method; content:"POST"; reference:url,blog.quarkslab.com/exploiting-glpi-during-a-red-team-engagement.html; reference:cve,2023-43813; classtype:web-application-attack; sid:2067156; rev:1; metadata:affected_product GLPI, attack_target Server, tls_state TLSDecrypt, created_at 2026_01_28, cve CVE_2023_43813, deployment Perimeter, deployment Interna
No public exploits indexed.
No writeups or analysis indexed.
2026-07-27
Published