PatchSiren

GravitLauncher CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL GravitLauncher CVE published 2026-09-17

CVE-2026-54617

CVE-2026-54617 debrief: Unauthenticated remote file read in GravitLauncher allows an attacker to read any file accessible to the LaunchServer process, potentially exposing sensitive information and enabling authentication bypass. The issue is fixed in version 5.7.12 and affects administrators and users of GravitLauncher, especially those with exposed LaunchServer instances. The vulnerability has a CVSS sc [truncated]