De multiples vulnérabilités ont été découvertes dans Mattermost Server. Elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données et un problème de sécurité non spécifié par l'éditeur.
Inadequate access control in the Hiperdino REST API Mon, 09/14/2026 - 13:27 Aviso Affected Resources Hiperdino REST API v1.0. Description INCIBE has coordinated the disclosure of a critical-severity vulnerability affecting the Hiperdino REST API, which acts as a bridge for carrying out actions automatically and in real time. The vulnerability was discovered by Jorge Ramos Santana.This vulnerability has been assigned the following code, CVSS v4.0 base score, CVSS vector and CWE vulnerability…
Exposure of private personal information to an unauthorized actor in Windows Biometric Service allows an authorized attacker to disclose information locally.
Exposure of private personal information to an unauthorized actor in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to disclose information locally.
Concurrent execution using shared resource with improper synchronization ('race condition') in Copilot Chat (Microsoft Edge) allows an authorized attacker to disclose information over a network.