CVE-2026-96538
Published 28 September 2026 · tracked since 28 September 2026
Description
WarehousePG (WHPG) 7.x before 7.6.0-WHPG is affected by a missing authorization vulnerability (CWE-862) in the built-in server-side file functions pg_file_write(text,text,bool), pg_file_rename(text,text,text), pg_file_unlink(text), and pg_logdir_ls(). These functions are executable by any authentica
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-93348 HIGH 8.1
- CVE-2026-88808 HIGH 8.8
- CVE-2026-101861 MEDIUM 4.1
- CVE-2026-101079 LOW 2.8
- CVE-2026-93539 MEDIUM 5.4
- CVE-2026-93537 MEDIUM 6.5
- CVE-2026-82929
- CVE-2026-82935
- CVE-2026-82323 HIGH 8.1
- CVE-2026-12265 HIGH 8.8