cve-2026-53521 let a stored future ddns profile id turn into another user ddns profile context later in nezha
cve-2026-53634 let authenticated sharp users bypass create authorization through quick creation command endpoints
cve-2026-49355 exposed private work package data through the single meeting agenda item api in openproject