MEDIUMVulnerability
Global

Gatehouse Bank launches refinance products for UK residents with no product or application fees

·Source: Finextra

Updated:

Executive Summary

Gatehouse Bank has launched limited edition two- and five- year Home Purchase Plan* (HPP) refinance products for UK residents, with no product or application fees.

Analysis

Gatehouse Bank has launched limited edition two- and five- year Home Purchase Plan* (HPP) refinance products for UK residents, with no product or application fees.
Source Attribution

Originally published by Finextra on Sep 4, 2026.

Related Threats

CRITICALVulnerabilityNEW

NVD CRITICAL: CVE-2026-86190 — WWBN AVideo contains a broken access control vulnerability in videoViewsInfo end...

WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and live session identifiers to unauthenticated callers when a hash parameter is provided. Attackers can use the disclosed session identifier to hijack viewer sessions, including administrator accounts, and obtain sensitive personal d

CVE-2026-86190
NIST NVD
CRITICALVulnerabilityNEW

NVD CRITICAL: CVE-2026-86189 — WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php th...

WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locations by supplying a caller-chosen path in the avideoRelativePath parameter. Attackers can replay any previously issued ciphertext as a notifyCode token, which is decrypted but never validated, to bypass authentication and write files to the applicatio

CVE-2026-86189
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-86184 — Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in t...

Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that allows unauthenticated attackers to authenticate as any user by email when APP_ENV is not production. Attackers can request the GET /screenshot-login/{email} endpoint with a registered email address to receive a fully authenticated session, enabling access to user administration, settings

CVE-2026-86184
NIST NVD