VYPR
AI Brief2026-07-26· generated Jul 26, 2026

Mod Proxy Cluster Admin Hijack, Oracle & Node.js Flaws Disclosed

Mod Proxy Cluster admin privileges can be hijacked, while Oracle E-Business Suite and Node.js libraries face critical vulnerabilities.

A critical impersonation header injection vulnerability in Mod Proxy Cluster's service-proxy component allows a low-privileged attacker to gain cluster-admin privileges on any managed cluster. This flaw, tracked as CVE-2026-17107, impacts all versions of cluster-proxy and could lead to complete cluster compromise. Immediate patching or mitigation is strongly advised.

Oracle E-Business Suite's Oracle HRMS (France) product is affected by CVE-2021-2316, a high-severity vulnerability that could allow a low-privileged attacker with network access to compromise the system. Supported versions 12.1.1 through 12.1.3 are impacted.

The auth0/node-jws library, a JSON Web Signature implementation for Node.js, contains an improper signature verification vulnerability in versions 3.2.2 and earlier, as well as version 4.0.0. Tracked as CVE-2025-65945, this flaw can be exploited under specific conditions when using the HS256 algorithm, potentially leading to signature bypass.

Several Linux kernel vulnerabilities were disclosed, including CVE-2026-64210, which involves an unlocked write to the ICOSQ in the net/mlx5e XSK component, and CVE-2026-64213, a missing lock protection in the hwmon lm90 driver. Additionally, CVE-2026-64236 addresses a division by zero in the i2c davinci driver, and CVE-2026-64233 fixes an issue in the usb gadget uvc component related to extension unit walks. As Vypr Intelligence reported, these and other kernel flaws highlight ongoing security challenges in complex systems.

A use-after-free vulnerability in the Linux kernel's pwrseq component, CVE-2026-64251, arises from improper handling of device freeing in pwrseq_debugfs_seq_next(). Separately, CVE-2026-56391 in GNU coreutils' uniq utility allows for an out-of-bounds read due to incorrect handling of multibyte input with the -w option, as detailed by Vypr Intelligence.

A code injection vulnerability in the gpsprof utility of Ntpsec (CVE-2026-60122) allows attackers to execute arbitrary OS commands by controlling GPS input data. This impacts gpsd through release-3.27.5. Other low-severity issues include a denial-of-service vulnerability in Juliangruber's brace-expansion library (CVE-2026-14257) and a potential NULL pointer dereference in the Linux kernel's drm/msm/a6xx driver (CVE-2026-64215).

Synthesized by Vypr AI