Atomicorp WAF Research Notes
Research Update - 2026-09-15
Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.
The entries published in this update represent research notes produced during ongoing analysis activities.
These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.
Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.
Presence means a positive research finding was published. Absence means no conclusion should be drawn.
CVE Notes Published in This Update
| CVE | Vulnerability Name | Rules Observed |
|---|---|---|
| CVE-2026-57124 | PraisonAI UI MCP connect endpoint allows unauthenticated local command execution | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390904 , 393655 |
| CVE-2026-57131 | praisonai: Jobs API exposes agent-execution endpoints with no authentication | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-86793 | SGLang Unsafe Deserialization Vulnerability | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-50006 | Anyquery: Arbitrary File Write (AFW) which could lead to Remote Code Execution (RCE) via Unrestricted ATTACH DATABASE in | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390501 , 390709 , 390716 , 390904 , 393655 |
| CVE-2026-55416 | Pimcore: SQL Injection in Mautic Custom Reports Bundle Due to Direct Concatenation of User-Controlled Configuration Fiel | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-82028 | Magistrala < 1.0.0 SQL Injection via format Parameter in Reader API | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-91771 | Weights & Biases wandb before 0.29.0 Path Traversal via File Download | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-15600 | SQL Injection in Alior Bank raty PrestaShop module | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-90699 | D-Link DWR-M920 formPinManageSetup sub_41E60C os command injection | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-57126 | praisonaiagents: SSRF guard validates literal IPs only and never resolves DNS | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-90702 | D-Link DWR-M921 formDiskFormat system os command injection | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-90703 | D-Link DWR-M921 formDiskCreateShare system os command injection | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-34151 | XWiki Platform: Resource path traversal via /skin/ action endpoint in Jetty 12+ | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-54629 | Anyquery: Local File Read (LFR) via Unrestricted SQLite Virtual Table Modules in Server Mode | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-57119 | PraisonAI: Unauthenticated Local File Inclusion via agent_file path in the Jobs API | 340007 , 344360 , 390709 |
| CVE-2026-57129 | PraisonAI: Arbitrary File Read via @file: Mention Path Traversal | 340007 , 344360 , 390709 |
| CVE-2026-91750 | WeKnora before 0.7.0 SSRF via Unvalidated HTTP Redirects | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-54150 | next-video: Unauthenticated arbitrary file read via /api/video request handler | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-91081 | Docs through 5.6.1 SSRF via Unauthenticated cors-proxy Endpoint | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-53708 | ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (/admin/gateways/test) | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-12767 | Langflow is vulnerable to server-side request forgery due to missing egress validation on server-side URL fetches | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-79573 | L-ONE v1.0.0 was discovered to SQL Injection Vulnerability | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-91079 | Huly Platform through 0.7.426 SSRF via Print Service | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-58191 | Appium base-driver <=10.6.0 - Reflected Cross-Site Scripting | 346755 |
| CVE-2026-90701 | subhajitkhan online-clinic-management-system listdoctor.php sql injection | 340017 |
| CVE-2026-90708 | Yot CMS Cookie global.php login sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-90789 | itsourcecode Leave Management System login.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-90841 | PHPGurukul Blood Donor Management System Report Endpoint Report.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-90843 | SabyasachiRana WebMap New Nmap Scan functions_nmap.py nmap_newscan os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-90844 | PHPGurukul Daily Expense Tracker System Login index.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-90849 | SourceCodester College Notes Gallery Management System login.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-90876 | SourceCodester Online Faculty Clearance System delete_requirement.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-90877 | SourceCodester Online Faculty Clearance System update_requirement_status.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-90879 | zyx0814 FilePress Publish search.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-91004 | SourceCodester Online Faculty Clearance System delete_faculty1.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2022-35497 | Cross-Site Scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-71802 | REBUILD 4.4.3 Cross-Site Scripting Vulnerability | 333140 |
| CVE-2026-91021 | Trillium Notes Cross-Site Scripting Vulnerability | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-91199 | Refly through 1.1.0 Server-Side Request Forgery via scrape endpoint | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-91772 | Halo through 2.26.1 Open Redirect via Unvalidated URI Parameter | 344365 |
| CVE-2026-90931 | LaraDashboard 0.9.0 through 1.2.2 Stored XSS via SVG Upload | 333140 , 333141 , 340095 , 340147 , 340148 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-79387 | PbootCMS versions 3.2.0 through 3.2.5 SQL Injection Vulnerability | 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-90700 | itsourcecode Sales and Inventory System pro_edit1.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-90795 | itsourcecode Loan Management System navbar.php cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259 |
| CVE-2026-90796 | itsourcecode Leave Management System index.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-90814 | cosmicstack-labs mercury-agent GitHub API github.ts githubRequest server-side request forgery | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-90857 | SourceCodester College Notes Gallery Management System Profile Upload userprofile.php unrestricted upload | 351000 |
| CVE-2026-91005 | SourceCodester Online Faculty Clearance System Profile Picture Upload edit_picture.php move_uploaded_file unrestricted u | 351000 |
| CVE-2026-90694 | SourceCodester Inventory Management System Customer Management customers_handler.php cross site scripting | 333140 , 340095 , 340147 , 341256 , 342259 , 346755 |
| CVE-2026-90695 | SourceCodester Inventory Management System Vendor Management vendors_handler.php cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-90696 | SourceCodester Inventory Management System Product Management products_handler.php cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-90705 | D-Link DWR-M921 Boa Dispatch Table formsysCmd os command injection | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-90706 | D-Link DWR-M921 formWsc os command injection | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-90709 | Yot CMS Admin Console admin.php eval code injection | 340014 , 344361 , 344363 , 344364 , 344366 , 344370 |
| CVE-2026-90788 | magicblack MacCMS10 Template .%40template%40default%40html%40label.html os command injection | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-90845 | PHPGurukul Daily Expense Tracker System sidebar.php cross site scripting | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2025-8538 | Portabilis i-Educar novo cross site scripting | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 |
| CVE-2025-8539 | Portabilis i-Educar public_distrito_cad.php cross site scripting | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-90850 | PHPGurukul Hostel Management System manage-students.php cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 347198 , 350147 , 350148 |