moltenbit

Security Research

45 disclosures 39 CVEs last update 2026-08-24

Security vulnerabilities I have responsibly disclosed. All findings were reported to the affected vendors and patched before public disclosure.

Disclosure ledger / 45

2026
CVE-2026-10627
Events Manager WordPress Plugin

missing authorization lets unauthenticated attackers use status, private, and private_only parameters to view draft, pending, trashed, or private event and location details

CVE-2026-74044
Wazuh

peer-controlled cluster hello node name lets an authenticated peer delete the contents of arbitrary manager directories on disconnect

CVE-2026-48024
Wazuh

merged-file header path traversal in cluster sync allows a cluster peer to write arbitrary files under WAZUH_PATH and reach root code execution

CVE-2026-49441
Wazuh

peer-controlled metadata key in cluster sync allows arbitrary file writes under WAZUH_PATH and root code execution on the manager

CVE-2026-46647
GlobaLeaks

insufficient role enforcement allows non-admin internal users on the root or management tenant to read and modify network configuration

No CVE
vinext

Authentication bypass via i18n locale prefix; middleware matcher evaluates unsanitized pathname

No CVE
vinext

Middleware header sanitization bypass; missing x-middleware-override-headers allows header spoofing

CVE-2026-58418
Gitea

SSRF via HTTP redirect in repository migration allows authenticated users to bypass internal address restrictions and reach localhost or private-network services

No CVE
Hushline

IDOR in FieldDefinition lets authenticated users alter or destroy other users’ submission fields and stored disclosure content

Hall of fame

HackerOne

Ranked among the top contributors of the program.