HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-61357 — Use after free in Application Information Services allows an authorized attacker...

·Source: NIST NVD

Updated:

Executive Summary

Use after free in Application Information Services allows an authorized attacker to elevate privileges locally.

Analysis

Use after free in Application Information Services allows an authorized attacker to elevate privileges locally. CVSS Score: 7.8. Published: 2026-08-11T17:18:10.473.

Indicators of Compromise (1)

CVE (1)
CVE-2026-61357
Source Attribution

Originally published by NIST NVD on Aug 11, 2026. Verified by: NIST.

Related Threats

CRITICALVulnerability

NVD CRITICAL: CVE-2026-74790 — Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering...

Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering MemberFilter changes, allowing reused TemplateContext instances to expose members that should be hidden. Attackers can access filtered properties and fields by reusing a TemplateContext after tightening its MemberFilter, bypassing sandbox policies across requests or tenants.

CVE-2026-74790
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-73061 — Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedOb...

Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that allows template code to write CLR object properties without setter-visibility checks. Attackers can modify properties with private, internal, or init-only setters, and perform mass assignment on public-setter properties, permanently altering live host objects after template rendering.

CVE-2026-73061
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-73056 — SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive...

SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive authentication attempts vulnerability in the CheckAuth() middleware. The middleware accepts the API token (Conf.Api.Token) via an Authorization header (Token/Bearer) or a ?token= query parameter, and neither path is protected by the application's CAPTCHA/lockout mechanism (NeedCaptcha/WrongAuthCount). As a result, an

CVE-2026-73056
NIST NVD