# 🚨 Weekly Self-Hosted Security Summary (October 01 – October 07, 2026)

**URL:** <https://forum.hhf.technology/t/weekly-self-hosted-security-summary-october-01-october-07-2026/4501>\
**Category:** 🚨→Security Advisory→🚨\
**Tags:** security, self-hosted, cve, weekly-security\
**Created:** [October 7, 2026, 6:31pm UTC](https://forum.hhf.technology/t/weekly-self-hosted-security-summary-october-01-october-07-2026/4501 "2026-10-07T18:31:48Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![hhf.technoloy](https://forum.hhf.technology/user_avatar/forum.hhf.technology/hhf.technoloy/32/68_2.png) [@hhf.technoloy](https://forum.hhf.technology/u/hhf.technoloy)\
**Post date:** [October 7, 2026, 6:31pm UTC](https://forum.hhf.technology/t/weekly-self-hosted-security-summary-october-01-october-07-2026/4501/1 "2026-10-07T18:31:48Z")

</div>

**Weekly Self-Hosted Security Summary (October 01 – October 07, 2026)**

Here’s a roundup of **11 critical/high security issues** disclosed or materially updated this week affecting popular open-source self-hosted projects. Patch quickly — several are actively exploitable.

* * *

### **1. Zammad Session Fixation → Remote Code Execution**

**CVE-2026-102489** | Disclosed: September 30, 2026  
**Project** : Zammad

**Technical Details** : A session-fixation vulnerability in Zammad can be chained to execute code as the `zammad` user. The flaw is practically exploitable on Zammad 6.5 and earlier because of the runtime environment used by those releases; 7.0+ is not practically exploitable under the documented conditions.

- **Severity** : Critical (CVSS 9.4)
- **Affected** : 6.3.0–6.5.4; the issue is also present in 7.0.0–7.1.3 but is not practically exploitable under the documented environment conditions
- **Fixed** : 6.5.4; Zammad 7.x is not practically exploitable, with additional hardening in 7.2.0
- **Workaround** : If you are still on 6.5 or older, take the instance offline or restrict access immediately and upgrade. Review logs and host activity for compromise indicators.

**Reference** : [Zammad Security Advisory](https://zammad.com/en/advisories/cve-2026-102489-cve-2026-102490)

### **2. Zammad Local Privilege Escalation**

**CVE-2026-102490** | Disclosed: September 30, 2026  
**Project** : Zammad

**Technical Details** : A local privilege-escalation flaw allows the `zammad` service account to elevate to root. It is not remotely exploitable by itself, but it becomes critical when chained after application-level compromise or local access.

- **Severity** : High (CVSS 8.5)
- **Affected** : 1.5.0 through 7.1.0-alpha
- **Fixed** : No CVE-specific fix publicly confirmed as of October 07, 2026; Zammad recommends upgrading to 7.2.x and restricting access to the underlying server while the issue is addressed
- **Workaround** : Restrict shell/host access to trusted administrators and do not expose the underlying server unnecessarily.

**Reference** : [DIVD CSIRT — CVE-2026-102490](https://csirt.divd.nl/cves/CVE-2026-102490/)

### **3. Plane Webhook Redirect SSRF**

**CVE-2026-105636** | Disclosed: October 05, 2026  
**Project** : Plane

**Technical Details** : Plane validates the original webhook URL against private and reserved ranges but follows redirects without re-validating the destination. A workspace user can redirect the webhook worker to an internal address or cloud metadata service and retrieve the response through webhook logs.

- **Severity** : Critical (CVSS 9.9)
- **Affected** : All versions before 1.4.0
- **Fixed** : 1.4.0
- **Workaround** : Disable or tightly restrict webhook creation until the instance is upgraded.

**Reference** : [NVD — CVE-2026-105636](https://nvd.nist.gov/vuln/detail/CVE-2026-105636)

### **4. Plane First-Admin Race Condition / Account Takeover**

**CVE-2026-104970** | Disclosed: October 05, 2026  
**Project** : Plane

**Technical Details** : During first-admin registration, concurrent unauthenticated requests could both observe that no administrator existed and create separate privileged accounts. An attacker racing the legitimate operator could therefore obtain instance-admin authority.

- **Severity** : High (CVSS 8.1)
- **Affected** : Versions from 0.13 through before 1.4.0
- **Fixed** : 1.4.0
- **Workaround** : Do not expose a new/uninitialized Plane instance to the public internet before completing initial administration and upgrading.

**Reference** : [NVD — CVE-2026-104970](https://nvd.nist.gov/vuln/detail/CVE-2026-104970)

### **5. Immich Authenticated SVG → RCE**

**CVE-2026-105764** | Disclosed: October 06, 2026  
**Project** : Immich

**Technical Details** : An authenticated non-admin user can upload a crafted SVG that reaches ImageMagick during thumbnail processing. Attacker-controlled SVG references can reach unsafe MSL/VIDEO coders and execute commands inside the `immich-server` container.

- **Severity** : High (CVSS 7.7)
- **Affected** : All versions before 3.2.4
- **Fixed** : 3.2.4
- **Workaround** : Treat untrusted users as a real security boundary and upgrade before accepting uploads from them.

**Reference** : [Immich Security Advisory](https://github.com/immich-app/immich/security/advisories/GHSA-q89f-h332-8q2h)

### **6. Twenty CRM Plaintext Credential Disclosure**

**CVE-2026-105763** | Disclosed: October 06, 2026  
**Project** : Twenty

**Technical Details** : The `/metadata` GraphQL `connectedAccounts` query returned connection parameters, including plaintext IMAP, SMTP, and CalDAV passwords, for connected accounts in a workspace. A normal workspace member could use the exposed credentials to access other users’ mail/calendar services and potentially reset third-party accounts.

- **Severity** : Critical (CVSS 9.6)
- **Affected** : 1.20.10 through before 2.7.0
- **Fixed** : 2.7.0
- **Workaround** : Rotate exposed external-service credentials after upgrading and review API access logs where available.

**Reference** : [NVD — CVE-2026-105763](https://nvd.nist.gov/vuln/detail/CVE-2026-105763)

### **7. Dify Unauthenticated Server-Side Request Forgery**

**CVE-2026-105762** | Disclosed: October 06, 2026  
**Project** : Dify

**Technical Details** : The `/console/api/remote-files/upload` endpoint accepted an attacker-controlled URL without authentication and caused the server to fetch it. A remote attacker could target internal services or cloud metadata and use the Dify host as a network pivot.

- **Severity** : High (CVSS 8.3)
- **Affected** : All versions before 1.13.0
- **Fixed** : 1.13.0
- **Workaround** : Restrict public exposure of the affected endpoint and block unnecessary server-side egress until upgraded.

**Reference** : [NVD / GitHub Advisory — CVE-2026-105762](https://github.com/langgenius/dify/security/advisories/GHSA-8235-vv5j-mmvg)

### **8. Payload CMS API Key Disclosure**

**CVE-2026-105849** | Disclosed: October 06, 2026  
**Project** : Payload CMS

**Technical Details** : When an authentication collection uses `useAPIKey`, users with ordinary read access to other authentication documents can retrieve active API keys. Those keys remain usable with the target account’s permissions until rotated or disabled.

- **Severity** : High (CVSS 8.8)
- **Affected** : 3.0.0 through before 3.90.0; 4.0.0-canary.0 through before 4.0.0-canary.34
- **Fixed** : 3.90.0 and 4.0.0-canary.34
- **Workaround** : Audit user-document read permissions and rotate potentially exposed API keys after upgrading.

**Reference** : [GitLab Advisory Database — CVE-2026-105849](https://advisories.gitlab.com/npm/payload/CVE-2026-105849/)

### **9. Payload CMS Password Access-Control Bypass**

**CVE-2026-105855** | Disclosed: October 06, 2026  
**Project** : Payload CMS

**Technical Details** : A field-level `access.update` restriction on an authentication collection’s password field was not correctly enforced server-side. A low-privilege authenticated user could therefore modify a password field that the application policy intended to protect.

- **Severity** : High (CVSS 8.1)
- **Affected** : All versions before 3.90.0; 4.0.0-canary.0 through before 4.0.0-canary.34
- **Fixed** : 3.90.0 and 4.0.0-canary.34
- **Workaround** : Review custom authentication collections that depend on field-level password restrictions and upgrade.

**Reference** : [NVD — CVE-2026-105855](https://nvd.nist.gov/vuln/detail/CVE-2026-105855)

### **10. Payload Ecommerce Order Double-Processing**

**CVE-2026-105850** | Disclosed: October 06, 2026  
**Project** : Payload CMS / `@payloadcms/plugin-ecommerce`

**Technical Details** : With the Stripe payment adapter, an order confirmation could be processed more than once under specific conditions. That can produce duplicate fulfillment or transaction handling, creating integrity and availability problems for self-hosted ecommerce deployments.

- **Severity** : Critical (CVSS 9.1)
- **Affected** : All versions before 3.90.0; 4.0.0-canary.0 through before 4.0.0-canary.34
- **Fixed** : 3.90.0 and 4.0.0-canary.34
- **Workaround** : Prioritize the upgrade on any deployment using the Stripe payment flow and review recent orders for duplicate confirmations.

**Reference** : [GitLab Advisory Database — CVE-2026-105850](https://advisories.gitlab.com/npm/%40payloadcms/plugin-ecommerce/CVE-2026-105850/)

### **11. Gitea Release Deletion Authorization Bypass**

**CVE-2026-105267** | Disclosed: October 06, 2026  
**Project** : Gitea

**Technical Details** : The tag-deletion route required Code write access but shared release-deletion logic without checking that the target was a plain tag. A collaborator with Code write access but without Releases permission could therefore delete published releases and their attachments.

- **Severity** : High (CVSS 8.1)
- **Affected** : Versions before 28.1.0
- **Fixed** : 28.1.0
- **Workaround** : Review repository collaborator permissions and restrict Code write access where release integrity is important.

**Reference** : [Gitea 28.1.0 Security Release](https://blog.gitea.com/release-of-28.1.0/)

* * *

## **Key Takeaways This Week**

- **Zammad remains the highest-priority alert** : CVE-2026-102489 is in CISA’s Known Exploited Vulnerabilities catalog, and the Zammad/DIVD case documents real-world abuse and urgent upgrade guidance.
- **SSRF and server-side processing remain dangerous trust boundaries** : Plane and Dify expose paths from apparently normal application features into internal services and metadata endpoints, while Immich turns crafted media into code execution.
- **Credential exposure is a major theme** : Twenty exposes plaintext external-service credentials to ordinary workspace members, while Payload can expose active API keys through normal document reads.
- **Authorization failures keep surfacing in self-hosted collaboration software** : Plane’s first-admin race, Payload’s password field restriction bypass, and Gitea’s release deletion issue all demonstrate why application-layer permission checks need testing.
- **Patch the whole application, not just the container image** : The fixes above are versioned application releases, and several affect specific plugins or deployment configurations.

**Recommendation** : Review your self-hosted stack this weekend and prioritize upgrades for any of the above projects you’re running.

Stay secure!

_Questions or need config help? Post in Help ._
