Atomicorp WAF Research Notes

Research Update - 2026-09-15

Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.

The entries published in this update represent research notes produced during ongoing analysis activities.

These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.

Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.

Presence means a positive research finding was published. Absence means no conclusion should be drawn.

CVE Notes Published in This Update

CVEVulnerability NameRules Observed
CVE-2026-57124PraisonAI UI MCP connect endpoint allows unauthenticated local command execution340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390904 , 393655
CVE-2026-57131praisonai: Jobs API exposes agent-execution endpoints with no authentication340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-86793SGLang Unsafe Deserialization Vulnerability340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-50006Anyquery: Arbitrary File Write (AFW) which could lead to Remote Code Execution (RCE) via Unrestricted ATTACH DATABASE in340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390501 , 390709 , 390716 , 390904 , 393655
CVE-2026-55416Pimcore: SQL Injection in Mautic Custom Reports Bundle Due to Direct Concatenation of User-Controlled Configuration Fiel340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-82028Magistrala < 1.0.0 SQL Injection via format Parameter in Reader API340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-91771Weights & Biases wandb before 0.29.0 Path Traversal via File Download340007 , 344360 , 347009 , 390709
CVE-2026-15600SQL Injection in Alior Bank raty PrestaShop module340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-90699D-Link DWR-M920 formPinManageSetup sub_41E60C os command injection340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-57126praisonaiagents: SSRF guard validates literal IPs only and never resolves DNS337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-90702D-Link DWR-M921 formDiskFormat system os command injection340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-90703D-Link DWR-M921 formDiskCreateShare system os command injection340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-34151XWiki Platform: Resource path traversal via /skin/ action endpoint in Jetty 12+340007 , 344360 , 347009 , 390709
CVE-2026-54629Anyquery: Local File Read (LFR) via Unrestricted SQLite Virtual Table Modules in Server Mode340007 , 344360 , 347009 , 390709
CVE-2026-57119PraisonAI: Unauthenticated Local File Inclusion via agent_file path in the Jobs API340007 , 344360 , 390709
CVE-2026-57129PraisonAI: Arbitrary File Read via @file: Mention Path Traversal340007 , 344360 , 390709
CVE-2026-91750WeKnora before 0.7.0 SSRF via Unvalidated HTTP Redirects337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-54150next-video: Unauthenticated arbitrary file read via /api/video request handler340007 , 344360 , 347009 , 390709
CVE-2026-91081Docs through 5.6.1 SSRF via Unauthenticated cors-proxy Endpoint337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-53708ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (/admin/gateways/test)337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-12767Langflow is vulnerable to server-side request forgery due to missing egress validation on server-side URL fetches337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-79573L-ONE v1.0.0 was discovered to SQL Injection Vulnerability340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-91079Huly Platform through 0.7.426 SSRF via Print Service337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-58191Appium base-driver <=10.6.0 - Reflected Cross-Site Scripting346755
CVE-2026-90701subhajitkhan online-clinic-management-system listdoctor.php sql injection340017
CVE-2026-90708Yot CMS Cookie global.php login sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-90789itsourcecode Leave Management System login.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-90841PHPGurukul Blood Donor Management System Report Endpoint Report.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-90843SabyasachiRana WebMap New Nmap Scan functions_nmap.py nmap_newscan os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-90844PHPGurukul Daily Expense Tracker System Login index.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-90849SourceCodester College Notes Gallery Management System login.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-90876SourceCodester Online Faculty Clearance System delete_requirement.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-90877SourceCodester Online Faculty Clearance System update_requirement_status.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-90879zyx0814 FilePress Publish search.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-91004SourceCodester Online Faculty Clearance System delete_faculty1.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2022-35497Cross-Site Scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-71802REBUILD 4.4.3 Cross-Site Scripting Vulnerability333140
CVE-2026-91021Trillium Notes Cross-Site Scripting Vulnerability333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-91199Refly through 1.1.0 Server-Side Request Forgery via scrape endpoint337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-91772Halo through 2.26.1 Open Redirect via Unvalidated URI Parameter344365
CVE-2026-90931LaraDashboard 0.9.0 through 1.2.2 Stored XSS via SVG Upload333140 , 333141 , 340095 , 340147 , 340148 , 342259 , 346755 , 350147 , 350148
CVE-2026-79387PbootCMS versions 3.2.0 through 3.2.5 SQL Injection Vulnerability340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-90700itsourcecode Sales and Inventory System pro_edit1.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-90795itsourcecode Loan Management System navbar.php cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259
CVE-2026-90796itsourcecode Leave Management System index.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-90814cosmicstack-labs mercury-agent GitHub API github.ts githubRequest server-side request forgery337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-90857SourceCodester College Notes Gallery Management System Profile Upload userprofile.php unrestricted upload351000
CVE-2026-91005SourceCodester Online Faculty Clearance System Profile Picture Upload edit_picture.php move_uploaded_file unrestricted u351000
CVE-2026-90694SourceCodester Inventory Management System Customer Management customers_handler.php cross site scripting333140 , 340095 , 340147 , 341256 , 342259 , 346755
CVE-2026-90695SourceCodester Inventory Management System Vendor Management vendors_handler.php cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-90696SourceCodester Inventory Management System Product Management products_handler.php cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-90705D-Link DWR-M921 Boa Dispatch Table formsysCmd os command injection340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-90706D-Link DWR-M921 formWsc os command injection340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-90709Yot CMS Admin Console admin.php eval code injection340014 , 344361 , 344363 , 344364 , 344366 , 344370
CVE-2026-90788magicblack MacCMS10 Template .%40template%40default%40html%40label.html os command injection340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-90845PHPGurukul Daily Expense Tracker System sidebar.php cross site scripting333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2025-8538Portabilis i-Educar novo cross site scripting333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2025-8539Portabilis i-Educar public_distrito_cad.php cross site scripting333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-90850PHPGurukul Hostel Management System manage-students.php cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 347198 , 350147 , 350148