CVE-2026-102811
Last modified
CVE-2026-102811 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Marmite through 0.4.2 contains missing authentication in the development server endpoints /__marmite__/content, /__marmite__/config, and /__marmite__/file/, allowing unauthenticated attackers to create, modify, and overwrite site content and configuration. Attackers can exploit unsanitized path parameters in handle_create_content and handle_clone_content to write files outside the project directory via directory traversal..
Description
Marmite through 0.4.2 contains missing authentication in the development server endpoints /__marmite__/content, /__marmite__/config, and /__marmite__/file/, allowing unauthenticated attackers to create, modify, and overwrite site content and configuration. Attackers can exploit unsanitized path parameters in handle_create_content and handle_clone_content to write files outside the project directory via directory traversal.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| rochacbruno | marmite | <= 0.4.2 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-102811?
How severe is CVE-2026-102811?
How do I fix CVE-2026-102811?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-102806OpenClaw before 2026.9.5 contains an incorrect authorization…6.3
- CVE-2026-102807OpenClaw before 2026.9.4 contains an incorrect authorization…5.3
- CVE-2026-102808PX4 Autopilot through 1.17.0 contains a NULL pointer derefer…6.5
- CVE-2026-102809PX4 Autopilot through 1.17.0 contains an uncontrolled stack …6.5
- CVE-2026-10281A weakness has been identified in Enderfga claw-orchestrator…7.3
- CVE-2026-102810Marmite through 0.4.2 contains a path traversal vulnerabilit…7.5
- CVE-2026-10282A security vulnerability has been detected in Bottelet Dayby…5.3
- CVE-2026-10283A vulnerability was detected in Bottelet DaybydayCRM up to 2…6.3
- CVE-2026-10284A flaw has been found in DevaslanPHP project-management up t…5.4
- CVE-2026-10285A vulnerability has been found in DevaslanPHP project-manage…5.4
- CVE-2026-10286A vulnerability was found in CodeAstro Payroll System 1.0. T…6.3
- CVE-2026-10287A vulnerability was determined in SourceCodester SEO Meta Ta…7.3
Are you affected by CVE-2026-102811?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
