Skip to content
Vulnerabilities Discovered in YunoHost-Apps and MyPresta Software

Vulnerabilities Discovered in YunoHost-Apps and MyPresta Software

First seen 30 Sep 2026, 21:37 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 30, 2026 at 22:31 UTC
  • •CVE-2026-74864 and CVE-2026-74865 allow unauthorized access to YunoHost-Apps.
  • •CVE-2026-85520 in MyPresta enables remote code execution via unauthorized file writes.
  • •All vulnerabilities have been patched in their respective software versions.

CERT Polska reported vulnerabilities in YunoHost-Apps and MyPresta software. The first vulnerability, CVE-2026-74864, allows unauthorized access by misconfiguring the HTTP header, enabling attackers to bypass authentication. The second vulnerability, CVE-2026-74865, permits attackers to log in as any user without proper authentication due to a configuration flaw. Both vulnerabilities were patched in version 5.8.0~ynh9 of YunoHost-Apps. Additionally, CVE-2026-85520 in MyPresta's Google Merchant Center Feed module allows unauthorized file writing and potential remote code execution, with a patch available in version 2.3.9. These vulnerabilities are, with CVSS scores of 9.3 and 9.2 respectively, and pose significant risks to affected systems.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-29
CVE-2026-85520 published
CERT Polska disclosed a critical vulnerability in MyPresta Google Merchant Center Feed allowing unauthorized file writes.
Cert.Pl
2026-09-30
CVE-2026-74864 and CVE-2026-74865 published
CERT Polska reported critical vulnerabilities in YunoHost-Apps sogo_yhn, allowing unauthorized access and bypassing authentication.
Cert.Pl

More articles in this cluster (4)

Following this threat?

Track CERT Polska and CVE-2026-74864 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What versions are affected by these vulnerabilities?
CVE-2026-74864 and CVE-2026-74865 affect YunoHost-Apps sogo_yhn, while CVE-2026-85520 affects MyPresta Google Merchant Center Feed.
What is the severity of these vulnerabilities?
CVE-2026-74864 and CVE-2026-85520 have a CVSS score of 9.3, making them critical, while CVE-2026-74865 has a CVSS score of 9.2.
Have these vulnerabilities been patched?
Yes, vulnerabilities in YunoHost-Apps were patched in version 5.8.0~ynh9, and MyPresta's issue was resolved in version 2.3.9.