freenode

← digests

Cluster of pre-auth RCE advisories across data platforms

Radar2026-08-18

Full Disclosure carried a set of security advisories describing critical remote code execution flaws in several enterprise data, analytics, and messaging products. Most of the issues are pre-authentication, carry CVSS scores of 9.8, and include public proof-of-concept details that raise immediate patching urgency for operators.

Pre-authentication RCE in DataStax Enterprise 6.8

Public disclosure described a pre-authentication remote code execution vulnerability in DataStax Enterprise 6.8.49 that reaches CVSS 9.8 via a Gremlin sandbox bypass. DataStax is the vendor involved. The combination of no authentication requirement and public details makes prompt assessment essential for any deployment exposing the affected interface.

Pre-authentication RCE in Confluent ksqlDB 7.9.1-ce

Confluent Platform ksqlDB 7.9.1-ce was the subject of a full-disclosure advisory for a pre-authentication remote code execution flaw rated CVSS 9.8 that abuses default unauthenticated endpoints and ships with a working proof of concept. Confluent, Inc. maintains the product. Operators who leave those endpoints reachable face straightforward remote compromise risk.

Pre-authentication RCE in ObjectDB 2.9.5 server mode

ObjectDB Software's ObjectDB 2.9.5 in server mode received a public advisory for pre-authentication remote code execution rated CVSS 9.8. The issue uses a JDOQL filter path that permits root-level command execution when default credentials are present. Any installation still running the default credential set is directly exposed.

Pre-authentication RCE in nanoDLP build 10729

A critical pre-authentication remote code execution vulnerability was disclosed in nanoDLP stable build 10729 from Nano3Dtech, accompanied by a public proof of concept and analysis. The flaw allows unauthenticated attackers to execute code on affected systems. Sites running the named build should isolate or upgrade the service without delay.

Pre-authentication RCE in Ontotext GraphDB 11.4.3 Free

Ontotext GraphDB 11.4.3 Free edition (Ontotext / Graphwise) was disclosed as containing an unauthenticated remote code execution vulnerability rated CVSS 9.8 that arises from unvalidated ruleset compilation. The advisory presents the issue as a public zero-day. Free-edition deployments that accept external rulesets are at immediate risk.

Pre-authentication RCE chain in Wyn Enterprise 9.1

Mescius (GrapeCity) Wyn Enterprise 9.1.00145.0 was the target of a single-message public disclosure describing an unauthenticated remote code execution chain rated CVSS 9.8 and supplied with a proof of concept. The chain requires no prior credentials. Installations reachable from untrusted networks inherit the full impact of the flaw.

Authenticated RCE via second-order SQL injection in Lansweeper

Lansweeper 12.2.1.0 (web reports 12.2.1.6) received a full-disclosure report of authenticated remote code execution rated CVSS 8.8 that is reached through second-order SQL injection. The commercial product is maintained by Lansweeper. Any environment that grants report-related privileges to less-trusted users should treat the issue as a privilege-escalation path to code execution.

Pre-authentication SYSTEM RCE in Output Messenger Server 2.0

Srimax Software (Output Technology) Output Messenger Server 2.0.x (versions at or above 2.0.63) was disclosed as a zero-day containing unauthenticated remote code execution to SYSTEM via Zip-Slip plugin planting. The product is a closed-source enterprise instant-messaging server. Exposure of the plugin-handling surface therefore grants unauthenticated full-system control.