started · updated
INCIBE reports vulnerabilities in EMSigner, Ghostscript, and Adobe Commerce
INCIBE has released a vulnerability bulletin detailing several security flaws in various software products.
Artifex Ghostscript (CVE-2023-36664) contains a high-severity vulnerability regarding improper permission validation for pipe devices. EMSigner v2.8.7 is affected by multiple issues, including a medium-severity Insecure Direct Object Reference (IDOR) that could allow unauthorized access to confidential user data, a high-severity access control flaw in the AdHoc user creation form, and a critical access control vulnerability in the 'Forgot Your Password' function that could allow unauthenticated attackers to access all registered accounts, including administrators.
Additionally, Adobe Commerce (CVE-2026-21291) has been identified with a medium-severity vulnerability affecting specific versions including 2.4.9-alpha3 and 2.4.8-p3.