cve-2026-54562 let non-admin cloudreve users with remote download permission fetch loopback and internal-only urls, then read the imported response body from their own files
cve-2026-10860 let a low-privileged galaxy editor delete another organisation galaxy in misp through a delete-path validation bypass
cve-2026-54256 let any authenticated backend user in wintercms target unrelated attachment records through the backend fileupload widget