CVE-2026-40097
Low Severity
Description
Step CA is an online certificate authority for secure, automated certificate management for DevOps. From 0.24.0 to before 0.30.0-rc3, an attacker can trigger an i...
Related Vulnerabilities
- CVE-2025-58913: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusio HIGH
- CVE-2026-35619: OpenClaw before 2026.3.24 contains an authorization bypass vulnerability in the HTTP /v1/models endp MEDIUM
- CVE-2026-30232: Chartbrew is an open-source web application that can connect directly to databases and APIs and use N/A
- CVE-2026-40178: ajenti.plugin.core has race conditions in 2FA MEDIUM
- CVE-2026-40259: SiYuan: Publish Reader Can Arbitrarily Delete Attribute View Files via `/api/av/removeUnusedAttribut HIGH
Related Coverage
Threat Actors