CVE-2026-59509 Details
Description
An unauthenticated improper input validation vulnerability in the POST /fetch_cve_data endpoint in cve-search. A remote attacker can manipulate request parameters controlling the MongoDB collection, projected fields, and regular-expression filters to read arbitrary application MongoDB collections. This can expose administrative usernames and password hashes from the mgmt_users collection, enabling offline password cracking and potential administrative account compromise.
A vulnerability has been identified in the cve-search application, specifically in version 6.0.0.dev20, within the POST /fetch_cve_data endpoint. This issue arises from improper input validation, allowing unauthenticated remote attackers to manipulate request parameters that control MongoDB collection access, projected fields, and regular-expression filters. Exploiting this vulnerability could lead to unauthorized reading of sensitive data from various MongoDB collections, including administrative usernames and password hashes from the mgmt_users collection. Such exposure could facilitate offline password cracking and potential compromise of administrative accounts.
The vulnerability has been addressed in cve-search version 6.0.1, which includes added server-side validations for the /fetch_cve_data endpoint inputs.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 5, 2026CISA-ADP
Assessed Jul 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/cve-search/cve-search/issues/1217 | CIRCL | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/cve-search/cve-search/pull/1218 | CIRCL | Issue TrackingVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | CIRCL |
Affected Products
| Product | Versions |
|---|---|
| cve-search | 6.0.0.dev20 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 6, 2026 | CVE Modified | CISA-ADP |
| Jul 5, 2026 | New CVE Received | CIRCL |
Volerion