Atomicorp WAF Research Notes

Research Update - 2026-09-22

Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.

The entries published in this update represent research notes produced during ongoing analysis activities.

These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.

Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.

Presence means a positive research finding was published. Absence means no conclusion should be drawn.

CVE Notes Published in This Update

CVEVulnerability NameRules Observed
CVE-2026-79920Ajenti: Privilege escalation to root via unauthenticated/unauthorized plugin install task340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-58491Warpgate: Reflected XSS in SSO return endpoint via attacker-controlled next parameter333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2025-12999Eclipse Open VSX Security Vulnerability337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-79916MaxKB AWS Bedrock model credential injection leads to remote code execution340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-55105Joplin: Fountain embeds allow arbitrary script execution in published notes and the note viewer333140
CVE-2026-76898draw.io: Unauthenticated SSRF via IPv6 ULA blocklist bypass in /embed2.js337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-59814Joplin: Stored XSS via inline-served note attachment on published shares333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-61647@roomi-fields/notebooklm-mcp has path traversal in vault.batch tool that allows arbitrary file write outside intended va340007 , 344360 , 390709
CVE-2026-52835Tautulli: Path traversal / arbitrary file write via unsanitized upload filename in import_config and import_database340007 , 344360 , 347009 , 390709
CVE-2026-63334draw.io: SSRF via DNS rebinding in ProxyServlet bypasses private IP blocklist337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-36468Cross-site Scripting (XSS) in index.php in CuteNews v.2.1.2 Vulnerability333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755
CVE-2026-55473HomeBox: Notifier SSRF guard misses NAT64 prefixes (64:ff9b::/96, 64:ff9b:1::/48) — generic:// URL reaches cloud metadat337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-61852Chartbrew: SQL Injection via row_limit Parameter in AI runQuery Tool340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 344360 , 344366 , 344370 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-39040BharatMLStack up to and including 1.3.0 Cross-Site Scripting Vulnerability333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-54915Tautulli: Open redirect via whitespace bypass in /auth/redirect344365
CVE-2026-45381Tautulli: Reflected XSS in /search endpoint333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259 , 350147 , 350148
CVE-2025-69904Linkstack 4.8.4 and Earlier Path Traversal Vulnerability344360 , 347009
CVE-2026-59816Joplin: Path traversal in transcribe proxy endpoint via URL-encoded slash340007 , 344360 , 347009 , 390709
CVE-2026-77522MaxKB: Authenticated full-read SSRF via the knowledge web-document import/sync crawler (Fork.fork requests.get, no inter337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-61681Hatchet: SSRF via Unsigned UnsubscribeURL in SNS UnsubscribeConfirmation Handler337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-91165Warpgate: Markup injection in SSO form_post return page via unencoded redirect/error values333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-94214ST Engineering iDirect Evolution/Velocity WebServer Evolution Management Service login.html redirect340165 , 344365
CVE-2026-94216ST Engineering iDirect Evolution/Velocity WebServer Evolution HTTP Header webserver authorize redirect340165 , 344365
CVE-2026-94145xuxueli xxl-job Task Management JobInfoController.java cross site scripting333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-94426xuxueli xxl-job insert cross site scripting333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-94150Omega Solution HRM OS SVG File Upload view cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-36470CuteNews v.2.1.2 Cross-Site Scripting Vulnerability333141 , 340003 , 340099 , 340158 , 341099 , 342259
CVE-2026-67827Incorrect Access Control in the HTTP API module in ZLMediaKit commit 9fd5152 Arbitrary Code Execution Vulnerability340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-88403nocobase v2.1.21 Server-Side Request Forgery Vulnerability337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-88756Pagekit CMS <= 1.0.18 SQL Injection Vulnerability340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572