<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>cloud — PoC Archive</title><link>https://poc.intelseclab.com/pocs/cloud/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 09 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/pocs/cloud/index.xml" rel="self" type="application/rss+xml"/><item><title>Apache Polaris — Cross-Tenant Credential Vending Before Location Validation in Iceberg REST Register (CVE-2026-64640)</title><link>https://poc.intelseclab.com/pocs/cloud/2026-08-09_cve-2026-64640-apache-polaris-cross-tenant-credential-vending/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/cloud/2026-08-09_cve-2026-64640-apache-polaris-cross-tenant-credential-vending/</guid><description>High severity (CVSS 8.1) — cloud · CVE-2026-64640. Status: Patched. Affects: Apache Polaris (Apache Iceberg REST catalog), registerTable and registerView endpoints. Tags: apache-polaris, iceberg, apache-iceberg, credential-vending, confused-deputy, authorization-bypass, cross-tenant, s3, storage, allowed-locations, CWE-441, CWE-639, CWE-918, ssrf, server-side-read, information-disclosure, register-table, register-view.</description><category>cloud</category><category>High</category><category>apache-polaris</category><category>iceberg</category><category>apache-iceberg</category><category>credential-vending</category><category>confused-deputy</category><category>authorization-bypass</category><category>cross-tenant</category><category>s3</category><category>storage</category><category>allowed-locations</category><category>CWE-441</category><category>CWE-639</category><category>CWE-918</category><category>ssrf</category><category>server-side-read</category><category>information-disclosure</category><category>register-table</category><category>register-view</category></item><item><title>tj-actions/branch-names GitHub Actions Command Injection (CVE-2025-54416)</title><link>https://poc.intelseclab.com/pocs/cloud/2026-07-06_cve-2025-54416-tj-actions-branch-names-command-injection/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/cloud/2026-07-06_cve-2025-54416-tj-actions-branch-names-command-injection/</guid><description>Critical severity (CVSS 9.1) — cloud · CVE-2025-54416. Status: PoC. Affects: tj-actions/branch-names GitHub Action. Tags: github-actions, ci-cd, command-injection, supply-chain, tj-actions, branch-names, secrets-exfiltration, shell-injection.</description><category>cloud</category><category>Critical</category><category>github-actions</category><category>ci-cd</category><category>command-injection</category><category>supply-chain</category><category>tj-actions</category><category>branch-names</category><category>secrets-exfiltration</category><category>shell-injection</category></item><item><title>RustFS Hardcoded gRPC Authentication Token Leading to Full Node Compromise (CVE-2025-68926)</title><link>https://poc.intelseclab.com/pocs/cloud/2026-07-06_cve-2025-68926-rustfs-grpc-token-bypass/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/cloud/2026-07-06_cve-2025-68926-rustfs-grpc-token-bypass/</guid><description>Critical severity (CVSS 9.8) — cloud · CVE-2025-68926. Status: Weaponized. Affects: RustFS (Rust-based S3-compatible distributed object storage) — internal node-to-node gRPC service. Tags: rustfs, grpc, hardcoded-credentials, authentication-bypass, object-storage, s3-compatible, information-disclosure, credential-theft, data-destruction, cwe-798, cwe-306.</description><category>cloud</category><category>Critical</category><category>rustfs</category><category>grpc</category><category>hardcoded-credentials</category><category>authentication-bypass</category><category>object-storage</category><category>s3-compatible</category><category>information-disclosure</category><category>credential-theft</category><category>data-destruction</category><category>cwe-798</category><category>cwe-306</category></item><item><title>IngressNightmare: Kubernetes ingress-nginx Admission Controller Shared-Library Injection RCE (CVE-2025-1974)</title><link>https://poc.intelseclab.com/pocs/cloud/2026-07-06_cve-2025-1974-ingressnightmare-nginx-admission-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/cloud/2026-07-06_cve-2025-1974-ingressnightmare-nginx-admission-rce/</guid><description>Critical severity (CVSS 9.8) — cloud · CVE-2025-1974. Status: Weaponized. Affects: Kubernetes ingress-nginx admission controller. Tags: kubernetes, ingress-nginx, ingressnightmare, admission-controller, nginx, ssl-engine, shared-library-injection, cluster-secrets, docker, python, c, cwe-94.</description><category>cloud</category><category>Critical</category><category>kubernetes</category><category>ingress-nginx</category><category>ingressnightmare</category><category>admission-controller</category><category>nginx</category><category>ssl-engine</category><category>shared-library-injection</category><category>cluster-secrets</category><category>docker</category><category>python</category><category>c</category><category>cwe-94</category></item><item><title>Supply Chain Command Injection in AWS CDK's NodejsFunction — CVE-2026-11417</title><link>https://poc.intelseclab.com/pocs/cloud/2026-07-05_cve-2026-11417-aws-cdk-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/cloud/2026-07-05_cve-2026-11417-aws-cdk-rce/</guid><description>High severity (CVSS 3.1) — cloud · CVE-2026-11417. Status: PoC. Affects: aws-cdk-lib (npm package), NodejsFunction L2 construct. Tags: aws, cdk, supply-chain, command-injection, esbuild, nodejs, ci-cd, rce.</description><category>cloud</category><category>High</category><category>aws</category><category>cdk</category><category>supply-chain</category><category>command-injection</category><category>esbuild</category><category>nodejs</category><category>ci-cd</category><category>rce</category></item><item><title>Spinnaker Clouddriver — Git Clone Shell Injection RCE (CVE-2026-32604)</title><link>https://poc.intelseclab.com/pocs/cloud/2026-07-05_cve-2026-32604-spinnaker-git-clone-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/cloud/2026-07-05_cve-2026-32604-spinnaker-git-clone-rce/</guid><description>Critical severity (CVSS 10) — cloud · CVE-2026-32604 (CWE-78). Status: PoC. Affects: Spinnaker (Clouddriver service) — continuous delivery / multi-cloud orchestration platform. Tags: spinnaker, clouddriver, command-injection, rce, cd-pipeline, cloud-credentials, shell-injection, docker-lab.</description><category>cloud</category><category>Critical</category><category>spinnaker</category><category>clouddriver</category><category>command-injection</category><category>rce</category><category>cd-pipeline</category><category>cloud-credentials</category><category>shell-injection</category><category>docker-lab</category></item><item><title>Sherlock CI `pull_request_target` Command Injection → GitHub Actions Secret Exfiltration (CVE-2026-44590)</title><link>https://poc.intelseclab.com/pocs/cloud/2026-07-05_cve-2026-44590-sherlock-pull-request-target-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/cloud/2026-07-05_cve-2026-44590-sherlock-pull-request-target-rce/</guid><description>Critical severity (CVSS 9.3) — cloud · CVE-2026-44590. Status: PoC. Affects: sherlock-project/sherlock (GitHub Actions workflow validate_modified_targets.yml). Tags: github-actions, pull_request_target, command-injection, ci-cd, supply-chain, token-exfiltration, sherlock.</description><category>cloud</category><category>Critical</category><category>github-actions</category><category>pull_request_target</category><category>command-injection</category><category>ci-cd</category><category>supply-chain</category><category>token-exfiltration</category><category>sherlock</category></item><item><title>RustFS — Presigned POST Policy Condition Bypass (CVE-2026-27607)</title><link>https://poc.intelseclab.com/pocs/cloud/2026-07-05_cve-2026-27607-rustfs-presigned-post-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/cloud/2026-07-05_cve-2026-27607-rustfs-presigned-post-bypass/</guid><description>High severity — cloud · CVE-2026-27607 (GHSA-w5fh-f8xh-5x3p). Status: PoC. Affects: RustFS (S3-compatible object storage server). Tags: rustfs, s3, object-storage, presigned-url, policy-bypass, aws-sdk, cloud-storage.</description><category>cloud</category><category>High</category><category>rustfs</category><category>s3</category><category>object-storage</category><category>presigned-url</category><category>policy-bypass</category><category>aws-sdk</category><category>cloud-storage</category></item><item><title>Plunk SSRF via Unvalidated AWS SNS SubscriptionConfirmation — CVE-2026-32096</title><link>https://poc.intelseclab.com/pocs/cloud/2026-07-05_cve-2026-32096-plunk-sns-ssrf/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/cloud/2026-07-05_cve-2026-32096-plunk-sns-ssrf/</guid><description>Critical severity (CVSS 9.3) — cloud · CVE-2026-32096. Status: PoC. Affects: Plunk (useplunk/plunk) email/webhook API. Tags: ssrf, aws-sns, imds, cloud-metadata, plunk, cwe-918, unauthenticated.</description><category>cloud</category><category>Critical</category><category>ssrf</category><category>aws-sns</category><category>imds</category><category>cloud-metadata</category><category>plunk</category><category>cwe-918</category><category>unauthenticated</category></item><item><title>OS Command Injection in KubeAI via Model URL (CVE-2026-34940)</title><link>https://poc.intelseclab.com/pocs/cloud/2026-07-05_cve-2026-34940-kubeai-ollama-command-injection/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/cloud/2026-07-05_cve-2026-34940-kubeai-ollama-command-injection/</guid><description>High severity (CVSS 8.7) — cloud · CVE-2026-34940. Status: PoC. Affects: KubeAI (github.com/kubeai-project/kubeai). Tags: kubernetes, kubeai, command-injection, ollama, crd, kubectl, model-serving, cwe-78.</description><category>cloud</category><category>High</category><category>kubernetes</category><category>kubeai</category><category>command-injection</category><category>ollama</category><category>crd</category><category>kubectl</category><category>model-serving</category><category>cwe-78</category></item><item><title>OpenLearnX Unauthenticated RCE via Container Volume Mount (CVE-2026-41900)</title><link>https://poc.intelseclab.com/pocs/cloud/2026-07-05_cve-2026-41900-openlearnx-container-volume-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/cloud/2026-07-05_cve-2026-41900-openlearnx-container-volume-rce/</guid><description>High severity (CVSS 8.6) — cloud · CVE-2026-41900 (GHSA-8h25-q488-4hxw). Status: PoC. Affects: OpenLearnX code-execution/compiler service (Flask backend). Tags: docker, container-escape, rce, unauthenticated, code-execution-sandbox, info-disclosure, volume-mount, root.</description><category>cloud</category><category>High</category><category>docker</category><category>container-escape</category><category>rce</category><category>unauthenticated</category><category>code-execution-sandbox</category><category>info-disclosure</category><category>volume-mount</category><category>root</category></item><item><title>Kubernetes `runAsNonRoot` Bypass via UID Integer Overflow (CVE-2026-46680)</title><link>https://poc.intelseclab.com/pocs/cloud/2026-07-05_cve-2026-46680-k8s-runasnonroot-uid-overflow/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/cloud/2026-07-05_cve-2026-46680-k8s-runasnonroot-uid-overflow/</guid><description>High severity — cloud · CVE-2026-46680. Status: PoC. Affects: Kubernetes (kubelet / container runtime UID handling). Tags: kubernetes, container-escape, runasnonroot, uid-overflow, security-context-bypass, privilege-escalation.</description><category>cloud</category><category>High</category><category>kubernetes</category><category>container-escape</category><category>runasnonroot</category><category>uid-overflow</category><category>security-context-bypass</category><category>privilege-escalation</category></item><item><title>HashiCorp go-getter Git Pathspec Arbitrary File Read (CVE-2026-4660)</title><link>https://poc.intelseclab.com/pocs/cloud/2026-07-05_cve-2026-4660-go-getter-terraform-pathspec-injection/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/cloud/2026-07-05_cve-2026-4660-go-getter-terraform-pathspec-injection/</guid><description>High severity (CVSS 7.5) — cloud · CVE-2026-4660 / HCSEC-2026-04. Status: PoC. Affects: hashicorp/go-getter (used by Terraform, Nomad, Packer, Waypoint). Tags: terraform, go-getter, git, pathspec-injection, arbitrary-file-read, ci-cd, supply-chain, iac.</description><category>cloud</category><category>High</category><category>terraform</category><category>go-getter</category><category>git</category><category>pathspec-injection</category><category>arbitrary-file-read</category><category>ci-cd</category><category>supply-chain</category><category>iac</category></item><item><title>Apache Flink Kubernetes Operator SSRF via jarURI (CVE-2026-40564)</title><link>https://poc.intelseclab.com/pocs/cloud/2026-07-05_cve-2026-40564-flink-k8s-operator-ssrf/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/cloud/2026-07-05_cve-2026-40564-flink-k8s-operator-ssrf/</guid><description>High severity — cloud · CVE-2026-40564. Status: PoC. Affects: Apache flink-kubernetes-operator. Tags: ssrf, kubernetes, flink, operator, kubernetes-operator, jarURI, cloud-metadata, crd.</description><category>cloud</category><category>High</category><category>ssrf</category><category>kubernetes</category><category>flink</category><category>operator</category><category>kubernetes-operator</category><category>jarURI</category><category>cloud-metadata</category><category>crd</category></item><item><title>Amazon WorkSpaces Skylight Workspace Config Service Local Privilege Escalation (CVE-2026-7791)</title><link>https://poc.intelseclab.com/pocs/cloud/2026-07-05_cve-2026-7791-aws-workspaces-skylight-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/cloud/2026-07-05_cve-2026-7791-aws-workspaces-skylight-lpe/</guid><description>High severity — cloud · CVE-2026-7791. Status: PoC. Affects: Amazon WorkSpaces — Skylight Workspace Config Service. Tags: aws, amazon-workspaces, skylight, toctou, privilege-escalation, arbitrary-file-write, windows, directory-junction.</description><category>cloud</category><category>High</category><category>aws</category><category>amazon-workspaces</category><category>skylight</category><category>toctou</category><category>privilege-escalation</category><category>arbitrary-file-write</category><category>windows</category><category>directory-junction</category></item><item><title>Nextcloud Federated Share OCM Bearer Token Scope Escalation to Sender WebDAV Access</title><link>https://poc.intelseclab.com/pocs/cloud/2026-07-03_nextcloud-federated-share-bearer-token-leak/</link><pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/cloud/2026-07-03_nextcloud-federated-share-bearer-token-leak/</guid><description>High severity — cloud · None assigned as of 2026-07-03. Status: PoC. Affects: Nextcloud Server — federated file sharing, OCM token exchange, WebDAV bearer authentication. Tags: nextcloud, federated-sharing, ocm, bearer-token, webdav, token-scope, authorization-bypass, oauth-like-flow.</description><category>cloud</category><category>High</category><category>nextcloud</category><category>federated-sharing</category><category>ocm</category><category>bearer-token</category><category>webdav</category><category>token-scope</category><category>authorization-bypass</category><category>oauth-like-flow</category></item><item><title>Gitea act_runner container.options Host Namespace Escape</title><link>https://poc.intelseclab.com/pocs/cloud/2026-07-03_gitea-act-runner-container-options-escape/</link><pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/cloud/2026-07-03_gitea-act-runner-container-options-escape/</guid><description>High severity — cloud · None assigned as of 2026-07-03. Status: PoC. Affects: Gitea Actions act_runner (Docker-backed). Tags: gitea, act-runner, ci-cd, docker, container-escape, host-namespace, privilege-escalation, capabilities.</description><category>cloud</category><category>High</category><category>gitea</category><category>act-runner</category><category>ci-cd</category><category>docker</category><category>container-escape</category><category>host-namespace</category><category>privilege-escalation</category><category>capabilities</category></item><item><title>Floci API Gateway VTL RCE + IAM Scope Bypass</title><link>https://poc.intelseclab.com/pocs/cloud/2026-07-03_floci-apigateway-vtl-rce/</link><pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/cloud/2026-07-03_floci-apigateway-vtl-rce/</guid><description>Critical severity — cloud · None assigned as of 2026-07-03. Status: Weaponized. Affects: Floci (AWS-compatible local cloud emulator). Tags: floci, api-gateway, velocity-template-language, rce, iam-bypass, sigv4, java-reflection, localstack-alternative.</description><category>cloud</category><category>Critical</category><category>floci</category><category>api-gateway</category><category>velocity-template-language</category><category>rce</category><category>iam-bypass</category><category>sigv4</category><category>java-reflection</category><category>localstack-alternative</category></item><item><title>Docker cp Copy-Out Destination Escape via Symlink Race</title><link>https://poc.intelseclab.com/pocs/cloud/2026-07-03_docker-cp-copyout-destination-escape/</link><pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/cloud/2026-07-03_docker-cp-copyout-destination-escape/</guid><description>Medium severity — cloud · None assigned as of 2026-07-03. Status: PoC. Affects: Docker Engine / CLI. Tags: docker, container-escape, toctou, symlink-race, docker-cp, path-traversal, archive-extraction, host-file-write.</description><category>cloud</category><category>Medium</category><category>docker</category><category>container-escape</category><category>toctou</category><category>symlink-race</category><category>docker-cp</category><category>path-traversal</category><category>archive-extraction</category><category>host-file-write</category></item><item><title>IngressNightmare - Kubernetes Ingress-NGINX Unauthenticated RCE</title><link>https://poc.intelseclab.com/pocs/cloud/2026-05-17_ingressnightmare-k8s-ingress-nginx-rce/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/cloud/2026-05-17_ingressnightmare-k8s-ingress-nginx-rce/</guid><description>Critical severity (CVSS 9.8) — cloud · CVE-2025-1974 (primary); also CVE-2025-1097, CVE-2025-1098, CVE-2025-24514. Status: Weaponized. Affects: Kubernetes Ingress-NGINX Controller (ingress-nginx). Tags: RCE, Kubernetes, ingress-nginx, admission-controller, unauthenticated, nginx-config-injection, cluster-takeover, k8s, shared-object, reverse-shell.</description><category>cloud</category><category>Critical</category><category>RCE</category><category>Kubernetes</category><category>ingress-nginx</category><category>admission-controller</category><category>unauthenticated</category><category>nginx-config-injection</category><category>cluster-takeover</category><category>k8s</category><category>shared-object</category><category>reverse-shell</category></item><item><title>Azure Networking Privilege Escalation via Missing Privilege Check</title><link>https://poc.intelseclab.com/pocs/cloud/2026-05-17_azure-networking-privilege-escalation/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/cloud/2026-05-17_azure-networking-privilege-escalation/</guid><description>Critical severity (CVSS 10) — cloud · CVE-2025-54914. Status: Researched. Affects: Microsoft Azure Networking service (GetRouteTable API). Tags: privilege-escalation, Azure, cloud, lateral-movement, API, routing, networking, no-user-interaction.</description><category>cloud</category><category>Critical</category><category>privilege-escalation</category><category>Azure</category><category>cloud</category><category>lateral-movement</category><category>API</category><category>routing</category><category>networking</category><category>no-user-interaction</category></item></channel></rss>