Security Digest: June 21, 2026 - 10 Critical Vulnerabilities

Today’s threat picture is urgent: multiple critical flaws allow remote code execution, privilege escalation, authentication bypass, and SQL injection across widely used apps and backend services. The highest-risk items are the SiYuan Bazaar XSS-to-RCE issues, Craft CMS admin RCE, and Capgo authorization flaws that can expose billing and identity data.

· 9 min read

Executive Summary

Today’s threat picture is urgent: multiple critical flaws allow remote code execution, privilege escalation, authentication bypass, and SQL injection across widely used apps and backend services. The highest-risk items are the SiYuan Bazaar XSS-to-RCE issues, Craft CMS admin RCE, and Capgo authorization flaws that can expose billing and identity data.

Act now: patch exposed systems immediately, disable or restrict vulnerable admin/RPC surfaces, and review logs for suspicious marketplace, SSO, RPC, and login activity.

Critical Vulnerabilities

CVE-2026-56397: SiYuan Bazaar XSS leading to remote code execution

Impact: Malicious package metadata or README content can execute JavaScript in Electron and escalate to OS command execution for any user browsing the Bazaar.

Affected Systems: SiYuan versions before v3.6.1

Immediate Action: Upgrade to v3.6.1 or later immediately. If you cannot patch, restrict Bazaar access and warn users not to browse untrusted packages.

Mitigation: Apply the vendor fix and review any third-party Bazaar content for suspicious HTML, scripts, or unexpected package metadata.

CVE-2026-56395: SiYuan Bazaar content injection enabling RCE

Impact: Attackers can inject HTML/JavaScript through package fields and trigger code execution through Electron nodeIntegration.

Affected Systems: SiYuan versions before v3.6.1

Immediate Action: Patch to v3.6.1 or later now. Treat Bazaar browsing as high risk until all clients are updated.

Mitigation: Update immediately; remove or quarantine untrusted packages and monitor endpoints for unexpected process launches.

CVE-2026-56396: phpMyFAQ authorization flaw allows SuperAdmin escalation

Impact: Authenticated admins with edit permissions can grant themselves SuperAdmin rights and take over the application.

Affected Systems: phpMyFAQ before 4.1.4

Immediate Action: Upgrade to 4.1.4 immediately. Review all admin accounts for unauthorized privilege changes.

Mitigation: Patch and audit recent changes to user roles, rights assignments, and admin activity logs.

CVE-2025-71348: picklescan misses malicious pickle payloads

Impact: Malicious pickle files can bypass detection and execute arbitrary code during deserialization, creating supply-chain risk.

Affected Systems: picklescan before 0.0.28

Immediate Action: Upgrade to 0.0.28 or later. Stop trusting pickle files from external or unverified sources.

Mitigation: Patch scanning pipelines, block untrusted pickle ingestion, and re-evaluate any artifacts accepted since the last clean scan.

CVE-2026-56239: Capgo billing function privilege escalation

Impact: Authenticated users may manipulate billing data for arbitrary organizations and deplete credits through a SECURITY DEFINER RPC.

Affected Systems: Capgo before 12.128.2

Immediate Action: Upgrade to 12.128.2 immediately and restrict RPC access until confirmed fixed.

Mitigation: Verify EXECUTE permissions on the function, audit overage events, and check for unauthorized billing changes.

CVE-2026-56242: Capgo API key oracle and identity disclosure

Impact: Attackers can confirm whether API keys are valid and map them to user IDs, then chain into organization and PII exposure.

Affected Systems: Capgo before 12.128.2

Immediate Action: Patch to 12.128.2 and rotate exposed API keys if this service is internet-accessible.

Mitigation: Disable unauthenticated access to the RPC, review API key usage, and look for enumeration patterns.

CVE-2026-12773: litellm MCP Proxy improper authentication

Impact: Remote attackers may bypass authentication in the MCP Proxy and access protected functionality.

Affected Systems: BerriAI litellm up to 1.59.8

Immediate Action: Upgrade above 1.59.8 now and restrict public exposure of the MCP Proxy.

Mitigation: Apply vendor updates, verify auth enforcement, and review proxy access logs for unauthorized sessions.

CVE-2026-12795: litellm SSO debug flow missing authentication

Impact: Attackers can reach SSO debug functionality without proper authentication, increasing the risk of account compromise and data exposure.

Affected Systems: BerriAI litellm up to 1.82.2

Immediate Action: Upgrade to a fixed release immediately and disable any debug endpoints exposed in production.

Mitigation: Patch, remove debug access from internet-facing environments, and audit SSO-related requests.

CVE-2026-12775: House-Rental-Management SQL injection in login.php

Impact: Remote attackers can inject SQL through the Username parameter, potentially leading to account compromise and database access.

Affected Systems: Montodel House-Rental-Management up to commit 90010017b81265eb1ef3810268909f7719a33863

Immediate Action: Remove public exposure of /login.php if possible and patch or replace the application immediately.

Mitigation: Apply vendor or repository fixes, validate input handling, and review database logs for injection patterns.

CVE-2026-56382: Craft CMS admin RCE via field layout preview

Impact: An authenticated admin can inject Yii2 event handlers to execute arbitrary PHP and exfiltrate secrets such as database credentials and CRAFT_SECURITY_KEY.

Affected Systems: Craft CMS 5.5.0 through 5.9.13

Immediate Action: Upgrade to 5.9.14 immediately. Restrict admin access until patched.

Mitigation: Apply the fix, rotate exposed secrets if compromise is suspected, and inspect admin actions involving field previews.

Previously Alerted

What to Do Now

  1. Patch internet-facing systems first, starting with SiYuan, Craft CMS, Capgo, phpMyFAQ, and litellm.
  2. Disable or restrict vulnerable endpoints including Bazaar browsing, RPC functions, debug flows, and admin preview features.
  3. Rotate credentials and API keys if any affected service was exposed externally or shows suspicious access.
  4. Review logs immediately for XSS payloads, unusual RPC calls, SQL injection attempts, and unexpected admin privilege changes.
  5. Verify versions against fixed releases before reopening access.

Verification steps:

  • Confirm each product is on a fixed version.
  • Check whether vulnerable functions are reachable from the network.
  • Validate that admin and API permissions have not changed unexpectedly.

Monitoring recommendations:

  • Alert on new SuperAdmin grants, billing anomalies, and unexpected key lookups.
  • Watch for Electron child processes, shell launches, and suspicious package metadata requests.
  • Monitor authentication failures, debug endpoint access, and SQL error spikes.

Related Resources

  • Internal blog posts: Add links to your June 21, 2026 incident guidance and patch validation notes when published.
  • Official vendor advisories: Check SiYuan, phpMyFAQ, Capgo, BerriAI litellm, Craft CMS, and the House-Rental-Management project release notes for fixed versions and mitigation guidance.

Keep reading