<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Api — PoC Archive</title><link>https://poc.intelseclab.com/tags/api/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 09 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/api/index.xml" rel="self" type="application/rss+xml"/><item><title>Ivanti Endpoint Manager Mobile (EPMM) Unauthenticated Remote API Access (CVE-2023-35078)</title><link>https://poc.intelseclab.com/pocs/network/2026-08-09_cve-2023-35078-ivanti-epmm-unauth-api-access/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-08-09_cve-2023-35078-ivanti-epmm-unauth-api-access/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2023-35078 (Ivanti advisory; CWE-287 per NVD). Status: Patched (Ivanti EPMM 11.8.1.1, 11.9.1.1, 11.10.0.2 and later). Affects: Ivanti Endpoint Manager Mobile (EPMM), previously branded MobileIron Core — the /mifs/aad/api/ administrative API surface. Tags: ivanti, epmm, mobileiron-core, mdm, authentication-bypass, cwe-287, unauthenticated, api, pii-disclosure, cisa-kev, ransomware, scanner.</description><category>network</category><category>Critical</category><category>ivanti</category><category>epmm</category><category>mobileiron-core</category><category>mdm</category><category>authentication-bypass</category><category>cwe-287</category><category>unauthenticated</category><category>api</category><category>pii-disclosure</category><category>cisa-kev</category><category>ransomware</category><category>scanner</category></item><item><title>Hoverfly Middleware Command Injection to RCE (CVE-2025-54123)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-54123-hoverfly-middleware-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-54123-hoverfly-middleware-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-54123. Status: Weaponized. Affects: SpectoLabs Hoverfly (HTTP/API service virtualization tool) — admin API, &lt;= v1.11.3. Tags: hoverfly, command-injection, middleware, api, token-auth, rce, cwe-78, python.</description><category>web</category><category>Critical</category><category>hoverfly</category><category>command-injection</category><category>middleware</category><category>api</category><category>token-auth</category><category>rce</category><category>cwe-78</category><category>python</category></item><item><title>FlowiseAI Account-Takeover via Forgot-Password Token Leak (CVE-2025-58434)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-58434-flowise-auth-bypass/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-58434-flowise-auth-bypass/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-58434. Status: Weaponized. Affects: FlowiseAI (/api/v1/account/forgot-password and /api/v1/account/reset-password endpoints). Tags: flowiseai, auth-bypass, account-takeover, forgot-password, reset-password, api, python, cwe-640.</description><category>web</category><category>Critical</category><category>flowiseai</category><category>auth-bypass</category><category>account-takeover</category><category>forgot-password</category><category>reset-password</category><category>api</category><category>python</category><category>cwe-640</category></item><item><title>YAMCS Unauthorized User Enumeration via IAM API (CVE-2026-44595)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-44595-yamcs-iam-user-enumeration/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-44595-yamcs-iam-user-enumeration/</guid><description>Medium severity (CVSS 4.3) — web · CVE-2026-44595 / GHSA-p2rj-mrmc-9w29. Status: PoC. Affects: yamcs-core (YAMCS mission control software). Tags: yamcs, iam, missing-authorization, user-enumeration, broken-access-control, api.</description><category>web</category><category>Medium</category><category>yamcs</category><category>iam</category><category>missing-authorization</category><category>user-enumeration</category><category>broken-access-control</category><category>api</category></item><item><title>Vaultwarden Organization Collection Permissions Bypass &amp; Cipher Enumeration (CVE-2026-26012)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-26012-vaultwarden-collection-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-26012-vaultwarden-collection-bypass/</guid><description>Medium severity (CVSS 6.5) — web · CVE-2026-26012 (GHSA-h265-g7rm-h337). Status: PoC. Affects: Vaultwarden (unofficial Bitwarden-compatible server). Tags: vaultwarden, bitwarden, password-manager, idor, access-control-bypass, api, cipher-enumeration, self-hosted.</description><category>web</category><category>Medium</category><category>vaultwarden</category><category>bitwarden</category><category>password-manager</category><category>idor</category><category>access-control-bypass</category><category>api</category><category>cipher-enumeration</category><category>self-hosted</category></item><item><title>SmarterMail Unauthenticated Admin Password Reset (CVE-2026-0001 / WT-2026-0001)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-0001-smartermail-password-reset/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-0001-smartermail-password-reset/</guid><description>Critical severity (CVSS 9) — web · CVE-2026-0001 (tracked publicly as WT-2026-0001). Status: PoC. Affects: SmarterTools SmarterMail (webmail/admin control panel), typically on port 9998. Tags: smartermail, auth-bypass, password-reset, email-server, unauthenticated, rce-chain, smartertools, api.</description><category>web</category><category>Critical</category><category>smartermail</category><category>auth-bypass</category><category>password-reset</category><category>email-server</category><category>unauthenticated</category><category>rce-chain</category><category>smartertools</category><category>api</category></item><item><title>Langflow Unauthenticated Remote Code Execution via `validate/code` Endpoint (CVE-2026-0770)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-0770-langflow-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-0770-langflow-rce/</guid><description>Critical severity — web · CVE-2026-0770. Status: PoC. Affects: Langflow (AI workflow builder). Tags: langflow, rce, unauthenticated, python, code-validation, exec, ai-platform, api.</description><category>web</category><category>Critical</category><category>langflow</category><category>rce</category><category>unauthenticated</category><category>python</category><category>code-validation</category><category>exec</category><category>ai-platform</category><category>api</category></item><item><title>Langflow Knowledge Base Path Traversal / Arbitrary Directory Deletion (CVE-2026-42048)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-42048-langflow-kb-path-traversal/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-42048-langflow-kb-path-traversal/</guid><description>High severity — web · CVE-2026-42048 (GHSA-9whx-c884-c68q). Status: PoC. Affects: Langflow (Knowledge Bases bulk delete API). Tags: langflow, path-traversal, arbitrary-file-deletion, cwe-22, api, docker-lab, knowledge-base.</description><category>web</category><category>High</category><category>langflow</category><category>path-traversal</category><category>arbitrary-file-deletion</category><category>cwe-22</category><category>api</category><category>docker-lab</category><category>knowledge-base</category></item><item><title>Grafana Dashboard Permissions Broken Access Control — Editor-to-Admin Privilege Escalation (CVE-2026-21721)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-21721-grafana-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-21721-grafana-lpe/</guid><description>High severity — web · CVE-2026-21721. Status: PoC. Affects: Grafana (self-hosted, dashboard permissions API). Tags: grafana, privilege-escalation, broken-access-control, dashboard-permissions, editor-to-admin, api.</description><category>web</category><category>High</category><category>grafana</category><category>privilege-escalation</category><category>broken-access-control</category><category>dashboard-permissions</category><category>editor-to-admin</category><category>api</category></item><item><title>Gitea OAuth2 Scope Enforcement Bypass via HTTP Basic Auth — CVE-2026-28699</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-28699-gitea-oauth2-scope-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-28699-gitea-oauth2-scope-bypass/</guid><description>High severity — web · CVE-2026-28699. Status: PoC. Affects: Gitea (code.gitea.io/gitea). Tags: gitea, oauth2, scope-bypass, basic-auth, incorrect-authorization, cwe-863, api.</description><category>web</category><category>High</category><category>gitea</category><category>oauth2</category><category>scope-bypass</category><category>basic-auth</category><category>incorrect-authorization</category><category>cwe-863</category><category>api</category></item><item><title>FortiAuthenticator Unauthenticated RCE Endpoint Probe (CVE-2026-44277)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-44277-fortiauthenticator-unauth-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-44277-fortiauthenticator-unauth-rce/</guid><description>Critical severity — web · CVE-2026-44277. Status: PoC. Affects: Fortinet FortiAuthenticator. Tags: fortinet, fortiauthenticator, unauthenticated-rce, api, endpoint-probe, detection.</description><category>web</category><category>Critical</category><category>fortinet</category><category>fortiauthenticator</category><category>unauthenticated-rce</category><category>api</category><category>endpoint-probe</category><category>detection</category></item><item><title>Coolify Authenticated Remote Command Injection via Deployment Config (CVE-2026-34038)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-34038-coolify-command-injection/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-34038-coolify-command-injection/</guid><description>Critical severity (CVSS 10) — web · CVE-2026-34038 (GHSA-qqrq-r9h4-x6wp). Status: PoC. Affects: Coolify (self-hosted PaaS/deployment platform). Tags: coolify, command-injection, cwe-78, rce, deployment, docker, api.</description><category>web</category><category>Critical</category><category>coolify</category><category>command-injection</category><category>cwe-78</category><category>rce</category><category>deployment</category><category>docker</category><category>api</category></item><item><title>Apache Superset Authenticated SQL Injection via sqlExpression/where Bypass — CVE-2026-23980</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-23980-superset-sqli/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-23980-superset-sqli/</guid><description>Medium severity (CVSS 6.5) — web · CVE-2026-23980. Status: PoC. Affects: Apache Superset. Tags: apache-superset, sql-injection, error-based-sqli, postgresql, authenticated, api, python, cwe-89.</description><category>web</category><category>Medium</category><category>apache-superset</category><category>sql-injection</category><category>error-based-sqli</category><category>postgresql</category><category>authenticated</category><category>api</category><category>python</category><category>cwe-89</category></item><item><title>Azure Networking Privilege Escalation via Missing Privilege Check</title><link>https://poc.intelseclab.com/pocs/cloud/2026-05-17_azure-networking-privilege-escalation/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/cloud/2026-05-17_azure-networking-privilege-escalation/</guid><description>Critical severity (CVSS 10) — cloud · CVE-2025-54914. Status: Researched. Affects: Microsoft Azure Networking service (GetRouteTable API). Tags: privilege-escalation, Azure, cloud, lateral-movement, API, routing, networking, no-user-interaction.</description><category>cloud</category><category>Critical</category><category>privilege-escalation</category><category>Azure</category><category>cloud</category><category>lateral-movement</category><category>API</category><category>routing</category><category>networking</category><category>no-user-interaction</category></item></channel></rss>