Atomicorp WAF Research Notes
Research Update - 2026-09-22
Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.
The entries published in this update represent research notes produced during ongoing analysis activities.
These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.
Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.
Presence means a positive research finding was published. Absence means no conclusion should be drawn.
CVE Notes Published in This Update
| CVE | Vulnerability Name | Rules Observed |
|---|---|---|
| CVE-2026-79920 | Ajenti: Privilege escalation to root via unauthenticated/unauthorized plugin install task | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-58491 | Warpgate: Reflected XSS in SSO return endpoint via attacker-controlled next parameter | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2025-12999 | Eclipse Open VSX Security Vulnerability | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-79916 | MaxKB AWS Bedrock model credential injection leads to remote code execution | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-55105 | Joplin: Fountain embeds allow arbitrary script execution in published notes and the note viewer | 333140 |
| CVE-2026-76898 | draw.io: Unauthenticated SSRF via IPv6 ULA blocklist bypass in /embed2.js | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-59814 | Joplin: Stored XSS via inline-served note attachment on published shares | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-61647 | @roomi-fields/notebooklm-mcp has path traversal in vault.batch tool that allows arbitrary file write outside intended va | 340007 , 344360 , 390709 |
| CVE-2026-52835 | Tautulli: Path traversal / arbitrary file write via unsanitized upload filename in import_config and import_database | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-63334 | draw.io: SSRF via DNS rebinding in ProxyServlet bypasses private IP blocklist | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-36468 | Cross-site Scripting (XSS) in index.php in CuteNews v.2.1.2 Vulnerability | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 |
| CVE-2026-55473 | HomeBox: Notifier SSRF guard misses NAT64 prefixes (64:ff9b::/96, 64:ff9b:1::/48) — generic:// URL reaches cloud metadat | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-61852 | Chartbrew: SQL Injection via row_limit Parameter in AI runQuery Tool | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 344360 , 344366 , 344370 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-39040 | BharatMLStack up to and including 1.3.0 Cross-Site Scripting Vulnerability | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-54915 | Tautulli: Open redirect via whitespace bypass in /auth/redirect | 344365 |
| CVE-2026-45381 | Tautulli: Reflected XSS in /search endpoint | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259 , 350147 , 350148 |
| CVE-2025-69904 | Linkstack 4.8.4 and Earlier Path Traversal Vulnerability | 344360 , 347009 |
| CVE-2026-59816 | Joplin: Path traversal in transcribe proxy endpoint via URL-encoded slash | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-77522 | MaxKB: Authenticated full-read SSRF via the knowledge web-document import/sync crawler (Fork.fork requests.get, no inter | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-61681 | Hatchet: SSRF via Unsigned UnsubscribeURL in SNS UnsubscribeConfirmation Handler | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-91165 | Warpgate: Markup injection in SSO form_post return page via unencoded redirect/error values | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-94214 | ST Engineering iDirect Evolution/Velocity WebServer Evolution Management Service login.html redirect | 340165 , 344365 |
| CVE-2026-94216 | ST Engineering iDirect Evolution/Velocity WebServer Evolution HTTP Header webserver authorize redirect | 340165 , 344365 |
| CVE-2026-94145 | xuxueli xxl-job Task Management JobInfoController.java cross site scripting | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-94426 | xuxueli xxl-job insert cross site scripting | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 |
| CVE-2026-94150 | Omega Solution HRM OS SVG File Upload view cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-36470 | CuteNews v.2.1.2 Cross-Site Scripting Vulnerability | 333141 , 340003 , 340099 , 340158 , 341099 , 342259 |
| CVE-2026-67827 | Incorrect Access Control in the HTTP API module in ZLMediaKit commit 9fd5152 Arbitrary Code Execution Vulnerability | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-88403 | nocobase v2.1.21 Server-Side Request Forgery Vulnerability | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-88756 | Pagekit CMS <= 1.0.18 SQL Injection Vulnerability | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |