Atomicorp WAF Research Notes

Research Update - 2026-09-01

Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.

The entries published in this update represent research notes produced during ongoing analysis activities.

These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.

Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.

Presence means a positive research finding was published. Absence means no conclusion should be drawn.

CVE Notes Published in This Update

CVEVulnerability NameRules Observed
CVE-2026-59111Command Injection vulnerability in eObčanka-Identifikace340014 , 347009 , 393655
CVE-2026-51152Server-Side Request Forgery337109 , 337110 , 340162 , 340163 , 344360 , 398001 , 398008 , 398021 , 398022
CVE-2026-82217Eclipse Theia Path Traversal Vulnerability340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-81889elFinder: SSRF protection bypass via DNS rebinding in the fsock_get_contents() fallback337109 , 337110 , 344360 , 347009 , 390722 , 398001 , 398021 , 398022
CVE-2026-82692D-Link DNS-340L/DNS-345 iscsi_mgr.cgi os command injection340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904 , 393655
CVE-2026-22244OpenMetadata Server-Side Template Injection (SSTI) in FreeMarker email templates that leads to RCE340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-61640Wallos: SSRF via OIDC Token/UserInfo URL Configuration337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398001 , 398021 , 398022
CVE-2026-82690D-Link DNS-327L/DNS-340L ve_mgr.cgi os command injection340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904 , 393655
CVE-2026-82691D-Link DNS-320L/DNS-327L/DNS-340L/DNS-345 CGI usb_device.cgi os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390904 , 393655
CVE-2026-61638Wallos: SSRF via Test Email Notification - unvalidated SMTP host/port337109 , 337110 , 340162 , 340163 , 344360 , 398001 , 398008 , 398021 , 398022
CVE-2026-77348Wallos incomplete fix for CVE-2026-33407: unauthenticated httpoxy SSRF still reachable via `endpoints/payments/search.ph337109 , 337110 , 340790 , 340791 , 344360 , 347009 , 390722 , 398001 , 398021 , 398022
CVE-2026-53553Goploy: Arbitrary File Read via Path Traversal in /deploy/fileDiff allows Remote Server Compromise340007 , 344360 , 390709
CVE-2026-79749MCPHub: SSRF Guard Bypass via IPv6 Transition Addresses in URL Validation337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398001 , 398008 , 398021 , 398022
CVE-2026-75132WAPT Server SQL Injection via /api/v3/hosts Endpoint340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-79747MCPHub vulnerable to SSRF: a non-admin user can make mcphub request arbitrary URLs and read the response (OpenAPI proxy337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398001 , 398008 , 398021 , 398022
CVE-2026-82877ILIAS before 9.22 Arbitrary File Read via SOAP addFile340007 , 344360 , 390709
CVE-2026-75592Kirby: Access to image files outside of the site root via path traversal in the media handling340007 , 344360 , 347009 , 390709
CVE-2026-79743MCPHub: Path Traversal via Malicious MCPB Manifest Name340007 , 344360 , 347009 , 390709
CVE-2026-82630PowerJob Transport Endpoint TestController.java MuConnectionManager.getOrCreateConnection server-side request forgery337109 , 337110 , 340162 , 340163 , 344360 , 398001 , 398008 , 398021 , 398022
CVE-2026-82701code-projects Online Shopping System Search Functionality action.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-82801NASA earthdata-search scale Endpoint handler.js scaleImage server-side request forgery337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398001 , 398021 , 398022
CVE-2026-82802NASA earthdata-search granules Endpoint handler.js OpenSearchGranuleSearchLambda server-side request forgery337109 , 337110 , 344360 , 398001 , 398008 , 398021 , 398022
CVE-2026-82396Sulu: Stored XSS via media download inline-disposition override333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-77352Wallos: Authenticated SSRF via per-user SMTP notification host (low-privilege user)337109 , 337110 , 344360 , 398001 , 398021 , 398022
CVE-2026-77351Wallos: SSRF via Unvalidated User-Level SMTP Host in Email Notification Settings337109 , 337110 , 340162 , 340163 , 344360 , 398001 , 398008 , 398021 , 398022
CVE-2026-82625code-projects Simple Inventory System User Registration register.php cross site scripting333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-82664yaojingang GEOFlow JSON-LD Theme HomeController.php cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-82679diem-project diem Widget Editor dmWidgetContentBaseMediaForm.php unrestricted upload351000
CVE-2026-82696itsourcecode Sales and Inventory System inv_searchfrm.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-82700code-projects Online Shopping System Newsletter Subscription offersmail.php cross site scripting333140 , 333141 , 340147 , 340148 , 341256 , 346755
CVE-2026-82905sdcb chats fetch-tools Endpoint McpController.cs McpController server-side request forgery337109 , 337110 , 344360 , 398001 , 398008 , 398021 , 398022
CVE-2026-83744invoiceninja Invoice Ninja invoices Endpoint Purify.php isHostSafe server-side request forgery337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398001 , 398021 , 398022
CVE-2026-82622code-projects Employee Leave Managing System Employee Profile Update editaction.php cross site scripting333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-82629jeecgboot jeewx-boot doUpload Endpoint MyJwWebJwid3Controller.java MyJwWebJwid3Controller.doUpload unrestricted upload351000
CVE-2026-82665yaojingang GEOFlow Image Library Cleanup ImageLibraryController.php unlink path traversal333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-82666yaojingang GEOFlow Superadmin Theme Editor SiteThemeEditorController.php preview code injection333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-82667yaojingang GEOFlow GenericHttpEndpointResolver.php DistributionController.isValidHttpEndpoint server-side request forger333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-82678diem-project diem Administrative Console actions.class.php executeCommand os command injection340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009
CVE-2026-82702Edimax BR-6214K asp_WlanMP Endpoint wlanMP.asp system os command injection340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-82703Edimax BR-6214K asp_setPing Endpoint ping.asp system os command injection340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655