PatchSiren

linqi GmbH CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH linqi GmbH CVE published 2026-06-05

CVE-2026-11369

CVE-2026-11369 is an Insecure Direct Object Reference (IDOR) vulnerability in the Comment API of an affected application. The vulnerability, with a CVSS score of 7.1 and HIGH severity, allows any authenticated user to read and write comments on any process across all business units by supplying an arbitrary object GUID. The CVE was published on 2026-06-05T14:16:35.657Z and last modified on 2026-06-05T16:07:31.547Z.

MEDIUM linqi GmbH CVE published 2026-06-05

CVE-2026-11346

A Server-Side Request Forgery (SSRF) vulnerability in the custom process creation feature of Linqi allows an authenticated attacker to probe internal network components. By crafting a specific process containing an HTTP Request component, an attacker can force the server to send arbitrary HTTP requests. By observing the varying application responses (Success, Failed, or 504 Gateway Time-out), the attacker [truncated]

MEDIUM linqi GmbH CVE published 2026-06-05

CVE-2026-11345

CVE-2026-11345 is an Improper Authentication vulnerability in the /api/Cdn/GetFile endpoint of linqi. This flaw allows unauthenticated, remote attackers to bypass file access controls by providing an 'AnonFile' query parameter containing exactly 256 characters. However, the actual security impact is negligible as the exposed resources are limited to minified JavaScript and CSS files that contain no sensit [truncated]

HIGH linqi GmbH CVE published 2026-06-05

CVE-2026-11347

CVE-2026-11347 is a HIGH-severity vulnerability in the linqi application. The application contains hardcoded cryptographic keys and uses a weak algorithm with a limited ASCII charset to dynamically generate Initialization Vectors (IVs) for AES/CBC encryption. This makes known-plaintext attacks feasible, allowing an attacker with local access to decrypt sensitive obfuscated strings, including ConnectionStr [truncated]