Saltar al contenido
  • Experiments
  • Notes
  • Scripts
  • Whoami
  • Labs
  • OrbiDump
header the dumpster
  • Experiments
  • Notes
  • Scripts
  • Whoami
  • Labs
  • OrbiDump
header the dumpster
  • Notes

CVE-2026-54086 Uncontrolled Memory Allocation in ESA sleapi-j

CVE-2026-54086 — Uncontrolled Memory Allocation in ESA sleapi-j

Severity: Moderate CVSS 3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected: sleapi-j < 5.1.7 Fixed in: sleapi-j 5.1.7 (commit 265118d) Advisory: GHSA-6g75-jwgj-hj8v Reporter: Daniel Miranda Barcelona (Excal1bur) Discovery date: 2026-03-26 This is the third YAMCS CVE. The first two were CVE-2026-44595 and CVE-2026-44596. What is…

  • Daniel Miranda Barcelona - Excal1bur
  • junio 25, 2026
  • Notes

CVE-2026-44595 User enumeration in YAMCS

User enum yamcs

Severity: MEDIUM (CVSS 4.3)Affected: yamcs-core < 5.12.7Fixed in: yamcs-core 5.12.7Advisory: GHSA-p2rj-mrmc-9w29 YAMCS has an IAM system with privilege levels. One of them is SystemPrivilege.ControlAccess supposed to gate access to user management endpoints. The IAM API has endpoints for listing users,…

  • Daniel Miranda Barcelona - Excal1bur
  • junio 2, 2026
  • Scripts

Vault Exfiltrator – USB Rubber Ducky Payload

vault_exfiltrator_portada

Vault Exfiltrator – USB Rubber Ducky Physical Exfiltration Payload Vault Exfiltrator is a payload designed for the USB Rubber Ducky that physically extracts password manager database files from a target Windows system. Unlike remote exfiltration payloads, it copies the files…

  • Daniel Miranda Barcelona - Excal1bur
  • abril 24, 2026
  • Responsible Security Disclosure

001. Coordinated Vulnerability Disclosure – Public Sector (Spain)

Coordinated report submitted through a national CERT. Context This section documents a real-world case of responsible security disclosure involving a public-sector system in Spain. The finding was identified through non-intrusive analysis and reported via an official channel, following the principles…

  • Daniel Miranda Barcelona - Excal1bur
  • enero 10, 2026

Copyright © 2026 Daniel Miranda Barcelona Excal1bur - From ZGZ with ❤️