Skip to main content

CVE-2026-24088

8.2
HIGHCVSS v3.1 Base Score

Cryptographic Issue while processing a specific partition which allows unauthorized write access to load a customized bootloader.

Published: 6/1/2026
Modified: 6/1/2026
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

8.2HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

CWE Classification

Related Vulnerabilities

Same Weakness Type(CWE-306)

CVE-2026-24090HIGH 7.1

Cryptographic issue while processing partition table entries allows unauthorized modification of boot flow.

6/1/2026
CVE-2026-41940CRITICAL 9.8

cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

4/29/2026
CVE-2026-6129HIGH 7.3

A vulnerability was detected in zhayujie chatgpt-on-wechat CowAgent up to 2.0.4. This affects an unknown function of the component Agent Mode Service. Performing a manipulation results in missing authentication. The attack can be initiated remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

4/12/2026
CVE-2026-39987CRITICAL 9.8

marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability. The terminal WebSocket endpoint /terminal/ws lacks authentication validation, allowing an unauthenticated attacker to obtain a full PTY shell and execute arbitrary system commands. Unlike other WebSocket endpoints (e.g., /ws) that correctly call validate_auth() for authentication, the /terminal/ws endpoint only checks the running mode and platform support before accepting connections, completely skipping authentication verification. This vulnerability is fixed in 0.23.0.

4/9/2026
CVE-2026-33017CRITICAL 9.8

Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint allows building public flows without requiring authentication. When the optional data parameter is supplied, the endpoint uses attacker-controlled flow data (containing arbitrary Python code in node definitions) instead of the stored flow data from the database. This code is passed to exec() with zero sandboxing, resulting in unauthenticated remote code execution. This is distinct from CVE-2025-3248, which fixed /api/v1/validate/code by adding authentication. The build_public_tmp endpoint is designed to be unauthenticated (for public flows) but incorrectly accepts attacker-supplied flow data containing arbitrary executable code. This issue has been fixed in version 1.9.0.

3/20/2026

Similar SeverityHIGH