References https://github.com/LandGrey/flink-unauth-rce https://www.exploit-db.com/exploits/48978 https://beaglesecurity.com/blog/vulnerability/apache-flink-unauth-rce.html https://s4e.io/tools/apache-flink-unauth-rce-vulnerability-scanner https://adamc95.medium.com/apache-flink-1-9-x-part-1-set-up-5d85fd2770f3 https://github.com/AleWong/Apache-Flink-Web-Dashboard-RCE https://blog.csdn.net/lx_lyt/article/details/103133361 https://github.com/murataydemir/CVE-2020-17519 https://cloud.tencent.com/developer/article/1544254 https://zhuanlan.zhihu.com/p/328382373 https://developer.aliyun.com/ask/639656 https://www.c0bra.xyz/2019/11/14/Apache-Flink-RCE-%E5%A4%8D%E7%8E%B0/ https://juejin.cn/post/6976258895316680741 https://www.cnblogs.com/Sylon/p/11868380.html https://www.rapid7.com/db/modules/exploit/multi/http/apache_flink_jar_upload_exec/ https://nsfocusglobal.com/advisory-apache-flink-remote-code-execution-vulnerability/
Related VulnerabilitiesPoCCVE-2026-10818: WPForms Pro <= 1.10.1.1 - Unauthenticated Arbitrary File UploadPoCCVE-2026-26216: Crawl4AI < 0.8.0 - Unauthenticated Remote Code Execution via Hooks ParameterPoCCVE-2026-29058: WWBN AVideo Encoder < 7.0 - Unauthenticated OS Command InjectionPoCCVE-2026-86242: Bifrost < 1.6.3 - Unauthenticated Remote Plugin URL FetchPoCApache Cocoon /xmlui/themes/Mirage2 目录遍历漏洞Apache Kafka UI /smartfilters/testexecutions 代码执行漏洞(CVE-2026-78166)PoCCVE-2026-12227: Visual Composer <= 45.16.0 - Unauthenticated LFIPoCCVE-2026-61560: GitLab MCP Server < 2.1.27 - Unauthenticated SSE Transport AccessPoCCVE-2026-89063: Bookly <=28.1 - IDOR Unauthenticated Sensitive Data AccessPoCmcp-streamable-http-exposure: MCP Streamable HTTP Server - Unauthenticated InitializePoCCVE-2026-6639: AI Copilot Content Generator <=1.4.6 - Unauthenticated Task Data ExposurePoCCVE-2026-80099: Newfold WordPress Plugins - Unauthenticated Admin Bypass via Empty HMAC SecretPoCpowerdns-monitor-exposure: PowerDNS Authoritative Server Monitor - Unauthenticated Exposure