Atomicorp WAF Research Notes

Research Update - 2026-08-29

Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.

The entries published in this update represent research notes produced during ongoing analysis activities.

These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.

Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.

Presence means a positive research finding was published. Absence means no conclusion should be drawn.

CVE Notes Published in This Update

CVEVulnerability NameRules Observed
CVE-2026-54745Kubeflow Pipelines: Unauthenticated SSRF and HTTP smuggling in Kubeflow Pipelines frontend /_proxy/ route, bypasses ENAB337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398001 , 398008 , 398021 , 398022
CVE-2026-55565Yamcs: Authenticated remote code execution via unescaped StreamSQL LIKE pattern compiled by Janino (LikeExpression)340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-55634Pimcore: Remote Code Execution via DataObject Class-Definition Field Name340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-55559Yamcs: Remote Code Execution via instance-template argument YAML injection (createInstance)344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-75337Yu AI Code Mother v4.3 is vulnerable to path traversal Vulnerability340007 , 344360 , 347009 , 390709
CVE-2016-6256SAP Business One for Android 1.2.3 - XML External Entity Injection344372
CVE-2026-82244Budibase before 3.41.3 Remote Code Execution via Plugin eval()340014 , 340023 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390719 , 393655
CVE-2026-19586Pre-Authentication OS Command Injection in Omada Gateways on OpenVPN Server in Omada Gateways340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-55511Yamcs: Authenticated RCE via StreamSQL aggregate-compiler column-name injection in Yamcs executeSql340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-55509WsgiDAV: Blind SQL injection in the MySQL provider340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-82286gpt-crawler Arbitrary File Write via outputFileName Parameter340007 , 344360 , 390709
CVE-2026-55245Bifrost: SSRF deny-list incomplete: isPublicIP permits CGNAT, IPv6 6to4/NAT64, and site-local in FetchAndEncodeURL337109 , 337110 , 344360 , 398001 , 398021 , 398022
CVE-2026-82270Portkey AI Gateway Server-Side Request Forgery via /v1/proxy/*337109 , 337110 , 340165 , 344360 , 347009 , 390719 , 390722 , 398001 , 398021 , 398022
CVE-2026-82278BISHENG Authenticated Arbitrary Python Code Execution via Workflow run_once340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-16061Rest Routes <= 5.5.5 - Unauthenticated SQLi via custom-tables/tables/{table_name}340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-75121PLANET GS-4210-16P2S Command Injection via dispatcher.cgi web_vlan_membership_edit_dialog_post340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-75122PLANET GS-4210-16P2S Command Injection via httpuploadcert.cgi340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-75123PLANET GS-4210-16P2S Command Injection via dispatcher.cgi web_smtp_test_post340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904 , 393655
CVE-2026-82243Budibase Server before 3.41.3 SSRF with Credential Leakage337109 , 337110 , 344360 , 398001 , 398008 , 398021 , 398022
CVE-2026-82262Logto Server-Side Request Forgery via webhook test endpoint337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398001 , 398021 , 398022
CVE-2019-10266Ahsay Backup 7.x - 8.1.1.50 - XML External Entity Injection344372
CVE-2026-55552Yamcs: Unauthenticated Directory Traversal340007 , 344360 , 347009 , 390709
CVE-2026-77939Flextype CMS 1.0.0-dev RCE via POST /api/v1/query Endpoint340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-82241Budibase backend-core SSRF via incomplete default blacklist337109 , 337110 , 344360 , 398001 , 398008 , 398021 , 398022
CVE-2026-55549Yamcs: Reflected XSS in the URL of the Authorize Endpoint333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2019-10263Ahsay Backup 7.x - 8.1.1.50 - XML External Entity Injection344372
CVE-2026-38725xipblog module 2.0.1 and Earlier for PrestaShop Cross-Site Scripting Vulnerability346755
CVE-2026-82274Twenty Open Redirect via OAuth Propagator Callback340162 , 340163 , 340165 , 344365
CVE-2026-82112houtini-ai houtini-lm code_task_files index.ts path traversal340007 , 344360 , 390709
CVE-2026-55566Yamcs: DOM XSS in Extension Routing333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-55834Pocket ID: Open Redirect on the OIDC /authorize page via unvalidated redirect_uri with prompt=none340162 , 340163 , 340165 , 344365