SBA Research is a research center for Information Security funded partly by the national initiative for COMET Competence Centers for Excellent Technologies.
SWUpdate before 2026.05 is affected by a time-of-check time-of-use (TOCTOU) race condition that allows local unprivileged attackers to escalate privileges to root or install untrusted contents using a signed update. Read More
Users can create alerts for customers that are not assigned to them. This can be abused to falsely attribute fake alerts to customers. In combination with Cross-Site Scripting, this can also be used to exfiltrate alerts from other customers. Read More
The IRIS web application is vulnerable to a Cross-site request forgery attack, because it uses the HTTP method GET to change state on the server. Read More
The IRIS web application does not properly validate uploaded files. It can therefore be misused to host phishing pages, amongst other things. This also creates an instance of a Cross-Site Scripting (XSS) vulnerability. Read More
The IRIS web application contains a weakness where an attacker can misuse it to redirect the user to a malicious website controlled by an attacker. Read More
GoAnywhere MFT before 7.10.0 is affected by an HTML injection vulnerability in its email templating functionality. If an attacker is able to influence the content of a template variable, malicious HTML can be embedded into outgoing emails generated by the application. As these messages originate from a trusted system, the vulnerability may facilitate phishing and other social-engineering attacks. The issue arises from insufficient HTML encoding of untrusted input before inclusion in HTML email content. Read More
LibreChat version 0.8.1-rc2 uses the same JWT secret for the user session mechanism and RAG API which compromises the service-level authentication of the RAG API. ... Read More
Checkmk in versions before 2.4.0p22 and 2.3.0p43 is prone to a cross-site scripting (XSS) vulnerability when used in a distributed monitoring setup. Any connected remote site can inject JavaScript code in the central site's user interface. ... Read More
SBA Research was delighted to welcome FFG Managing Director Karin Tausz and Head of Division Structural Programmes Silvia Laimgruber to the SBA-K1 NGC COMET Center in Vienna. ... ∞
Our colleague Nicholas Stifter, researcher and security analyst at SBA Research, presented his conference paper titled Reuse of Public Keys Across UTXO and Account-Based Cryptocurrencies at the Financial Cryptography and Data Security 2026 in St. Kitts, USA. ... ∞
Tanja Sarcevic, Daryna Olyinyk, and Yelyzaveta Klysa, all MLDM research group members, and Sabina Khazari participated in the European Cybersecurity & AI Hackathon Championship organized by CISPA, one of Europe’s leading research centers in cybersecurity and artificial intelligence. Congratulations to them, they won 2nd place and qualified themselves to the grand finale that will be held in St. Ingbert, Germany, in June 2026. ... ∞