PoC Archive PoC Archive

tag

Confused-Deputy

  • CVE-2026-64640 cloud HIGH 8.1

    Apache Polaris — Cross-Tenant Credential Vending Before Location Validation in Iceberg REST Register (CVE-2026-64640)

    CVE-2026-64640 is a confused-deputy vulnerability in Apache Polaris: the Iceberg REST register endpoints mint cloud storage credentials for a caller-supplied path and read that path server-side before checking it against the catalog's allowedLocations. A…

    Patched 2026-08-09
  • None assigned as of 2026-07-03 binary HIGH

    System Informer phsvc Trusted-Host Confused Deputy LPE

    System Informer's privileged helper process phsvc exposes an ALPC API port (\BaseNamedObjects\SiSvcApiPort) with a connect ACL open to Everyone, and authorizes connecting clients purely by checking whether the client's process image is generically…

    Unverified 2026-07-03