CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-69079

unknowncovered by 1 sourcefirst seen 2026-08-03
CTI-Transmute contains an uncontrolled resource-consumption vulnerability in the unauthenticated /activity_timeline endpoint. The endpoint accepts a user-controlled days query parameter that was not restricted to a reasonable range. A remote, unauthenticated attacker could submit an excessively large value for this parameter, causing the application to retrieve and process activity data over an arbitrarily large period. This could consume excessive database, CPU, or memory resources, delay the processing of concurrent requests, or trigger an internal server error. Repeated requests could further degrade the availability of the CTI-Transmute website. The vulnerability is corrected by clamping the requested timeline range to a minimum of one day and a maximum of 1,095 days.

⚡ Watch CVE-2026-69079

Get an email if CVE-2026-69079 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2026-69079

CVE.org record

Embed the live status

CVE-2026-69079 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-69079 status](https://www.csirts.com/badge/CVE-2026-69079)](https://www.csirts.com/cve/CVE-2026-69079)