PatchSiren

disconf CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL disconf CVE published 2026-08-26

CVE-2026-75338

CVE-2026-75338 debrief based on the supplied source corpus. The disconf (Distributed Configuration Management Platform) 2.6.36 has a vulnerability in the config-fetching APIs /api/config/item, /api/config/file, /api/config/list, and /api/config/simple/list, which are exposed without authentication due to the LoginInterceptor whitelisting these paths. This allows anonymous attackers to read configuration i [truncated]