CVE-2026-56355
published 2026-06-20CVE-2026-56355: GNU Savannah Administration Savane through 3.17 uses untrusted data as part of authorization.
PriorityP417low3.7CVSS 3.1
AVNACHPRNUINSUCLINAN
EPSS
0.35%
27.2th percentile
GNU Savannah Administration Savane through 3.17 uses untrusted data as part of authorization.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | savane | 3.14 – 3.17 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
GNU Savane up to 3.17 incorrect behavior order (EUVD-2026-38135)
vuldb·2026-06-21·CVSS 3.7
CVE-2026-56355 [LOW] GNU Savane up to 3.17 incorrect behavior order (EUVD-2026-38135)
A vulnerability, which was classified as problematic, has been found in GNU Savane up to 3.17. Affected is an unknown function. The manipulation leads to incorrect behavior order.
This vulnerability is traded as CVE-2026-56355. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to install a patch to address this issue.
GHSA
GNU Savannah Administration Savane through 3.17 uses untrusted data as part of authorization.
ghsa_unreviewed·2026-06-20
CVE-2026-56355 [LOW] CWE-696 GNU Savannah Administration Savane through 3.17 uses untrusted data as part of authorization.
GNU Savannah Administration Savane through 3.17 uses untrusted data as part of authorization.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://cgit.git.savannah.gnu.org/cgit/administration/savane.git/tree/frontend/php/file.php?h=release-3.17#n113https://cgit.git.savannah.gnu.org/cgit/administration/savane.git/tree/frontend/php/file.php?h=release-3.17#n123https://news.ycombinator.com/item?id=48605220https://www.fsf.org/news/statement-regarding-gnu-savannah-security-reportshttps://www.hacktron.aihttps://www.mallory.ai/stories/019ee445-bdd4-7775-93b5-a8faaf5c2eb7
2026-06-20
Published