PatchSiren

uber CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH uber CVE published 2026-09-16

CVE-2026-92791

CVE-2026-92791 debrief based on the supplied source corpus. The vulnerability is a path traversal issue in Uber Kraken through 0.1.29, allowing unauthenticated attackers to read arbitrary files by manipulating the tag parameter in the /tags/{tag} endpoint. This could lead to unauthorized access to sensitive files and data. Defenders should assess exposure and verify configurations to prevent such attacks. [truncated]