Multiple Vulnerabilities Discovered in kerwincui FastBee Software
Article Content
- •CVE-2026-7676 allows path traversal in FastBee's Tool Download Endpoint.
- •CVE-2026-7677 enables cross-site scripting in the System Notice Handler.
- •Both vulnerabilities can be exploited remotely and have been publicly disclosed.
Two critical vulnerabilities have been identified in kerwincui FastBee versions up to 1.2.1. CVE-2026-7676 affects the Tool Download Endpoint, allowing path traversal through the fileName argument in the ToolController.download function. CVE-2026-7677 impacts the System Notice Handler, enabling cross-site scripting via the noticeContent argument in the SysNoticeController.Add function. Both vulnerabilities can be exploited remotely, and the exploits have been publicly disclosed. The vendor was contacted prior to disclosure but did not respond. These vulnerabilities pose significant risks to users of the FastBee software, potentially leading to unauthorized access and data manipulation. Immediate attention is required for affected systems to mitigate these risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-7676 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…