PatchSiren

retspen CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH retspen CVE published 2026-09-16

CVE-2026-92761

WebVirtCloud has a high-severity vulnerability allowing view-only users to perform privileged actions due to improper validation of permission flags in UserInstance grants. This issue enables attackers with read-only grants to power off virtual machines, reset root passwords, install SSH keys, and manage ISO images by exploiting the get_instance gate. The vulnerability arises from the improper validation [truncated]