Atomicorp WAF Research Notes
Research Update - 2026-08-29
Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.
The entries published in this update represent research notes produced during ongoing analysis activities.
These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.
Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.
Presence means a positive research finding was published. Absence means no conclusion should be drawn.
CVE Notes Published in This Update
| CVE | Vulnerability Name | Rules Observed |
|---|---|---|
| CVE-2026-54745 | Kubeflow Pipelines: Unauthenticated SSRF and HTTP smuggling in Kubeflow Pipelines frontend /_proxy/ route, bypasses ENAB | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398001 , 398008 , 398021 , 398022 |
| CVE-2026-55565 | Yamcs: Authenticated remote code execution via unescaped StreamSQL LIKE pattern compiled by Janino (LikeExpression) | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-55634 | Pimcore: Remote Code Execution via DataObject Class-Definition Field Name | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-55559 | Yamcs: Remote Code Execution via instance-template argument YAML injection (createInstance) | 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-75337 | Yu AI Code Mother v4.3 is vulnerable to path traversal Vulnerability | 340007 , 344360 , 347009 , 390709 |
| CVE-2016-6256 | SAP Business One for Android 1.2.3 - XML External Entity Injection | 344372 |
| CVE-2026-82244 | Budibase before 3.41.3 Remote Code Execution via Plugin eval() | 340014 , 340023 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390719 , 393655 |
| CVE-2026-19586 | Pre-Authentication OS Command Injection in Omada Gateways on OpenVPN Server in Omada Gateways | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-55511 | Yamcs: Authenticated RCE via StreamSQL aggregate-compiler column-name injection in Yamcs executeSql | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-55509 | WsgiDAV: Blind SQL injection in the MySQL provider | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-82286 | gpt-crawler Arbitrary File Write via outputFileName Parameter | 340007 , 344360 , 390709 |
| CVE-2026-55245 | Bifrost: SSRF deny-list incomplete: isPublicIP permits CGNAT, IPv6 6to4/NAT64, and site-local in FetchAndEncodeURL | 337109 , 337110 , 344360 , 398001 , 398021 , 398022 |
| CVE-2026-82270 | Portkey AI Gateway Server-Side Request Forgery via /v1/proxy/* | 337109 , 337110 , 340165 , 344360 , 347009 , 390719 , 390722 , 398001 , 398021 , 398022 |
| CVE-2026-82278 | BISHENG Authenticated Arbitrary Python Code Execution via Workflow run_once | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-16061 | Rest Routes <= 5.5.5 - Unauthenticated SQLi via custom-tables/tables/{table_name} | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-75121 | PLANET GS-4210-16P2S Command Injection via dispatcher.cgi web_vlan_membership_edit_dialog_post | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-75122 | PLANET GS-4210-16P2S Command Injection via httpuploadcert.cgi | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-75123 | PLANET GS-4210-16P2S Command Injection via dispatcher.cgi web_smtp_test_post | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904 , 393655 |
| CVE-2026-82243 | Budibase Server before 3.41.3 SSRF with Credential Leakage | 337109 , 337110 , 344360 , 398001 , 398008 , 398021 , 398022 |
| CVE-2026-82262 | Logto Server-Side Request Forgery via webhook test endpoint | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398001 , 398021 , 398022 |
| CVE-2019-10266 | Ahsay Backup 7.x - 8.1.1.50 - XML External Entity Injection | 344372 |
| CVE-2026-55552 | Yamcs: Unauthenticated Directory Traversal | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-77939 | Flextype CMS 1.0.0-dev RCE via POST /api/v1/query Endpoint | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-82241 | Budibase backend-core SSRF via incomplete default blacklist | 337109 , 337110 , 344360 , 398001 , 398008 , 398021 , 398022 |
| CVE-2026-55549 | Yamcs: Reflected XSS in the URL of the Authorize Endpoint | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2019-10263 | Ahsay Backup 7.x - 8.1.1.50 - XML External Entity Injection | 344372 |
| CVE-2026-38725 | xipblog module 2.0.1 and Earlier for PrestaShop Cross-Site Scripting Vulnerability | 346755 |
| CVE-2026-82274 | Twenty Open Redirect via OAuth Propagator Callback | 340162 , 340163 , 340165 , 344365 |
| CVE-2026-82112 | houtini-ai houtini-lm code_task_files index.ts path traversal | 340007 , 344360 , 390709 |
| CVE-2026-55566 | Yamcs: DOM XSS in Extension Routing | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-55834 | Pocket ID: Open Redirect on the OIDC /authorize page via unvalidated redirect_uri with prompt=none | 340162 , 340163 , 340165 , 344365 |