{
    "document": {
        "category": "csaf_base",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE"
            }
        },
        "lang": "en",
        "notes": [
            {
                "category": "legal_disclaimer",
                "text": "The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this portal to enhance access to its information and vulnerabilities. The use of this information is subject to the following terms and conditions:\n\nThe vulnerabilities disclosed in this portal are gathered by NCSC-NL from a variety of open sources, which the user can retrieve from other platforms. NCSC-NL makes every reasonable effort to ensure that the content of this portal is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or real-time keeping up-to-date. NCSC-NL does not control nor guarantee the accuracy, relevance, timeliness or completeness of information obtained from these external sources. The vulnerabilities disclosed in this portal are intended solely for the convenience of professional parties to take appropriate measures to manage the risks posed to the cybersecurity. No rights can be derived from the information provided therein.\n\nNCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of the vulnerabilities disclosed in this portal. This includes damage resulting from the inaccuracy of incompleteness of the information contained in it.\nThe information on this page is subject to Dutch law. All disputes related to or arising from the use of this portal regarding the disclosure of vulnerabilities will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings."
            }
        ],
        "publisher": {
            "category": "coordinator",
            "contact_details": "cert@ncsc.nl",
            "name": "National Cyber Security Centre",
            "namespace": "https://www.ncsc.nl/"
        },
        "title": "CVE-2026-27012",
        "tracking": {
            "current_release_date": "2026-03-27T13:52:21.138712Z",
            "generator": {
                "date": "2026-02-17T15:00:00Z",
                "engine": {
                    "name": "V.E.L.M.A",
                    "version": "1.7"
                }
            },
            "id": "CVE-2026-27012",
            "initial_release_date": "2026-03-03T19:09:02.382224Z",
            "revision_history": [
                {
                    "date": "2026-03-03T19:09:02.382224Z",
                    "number": "1",
                    "summary": "CVE created.| Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (2).| CWES updated (1)."
                },
                {
                    "date": "2026-03-03T19:09:04.733410Z",
                    "number": "2",
                    "summary": "NCSC Score created."
                },
                {
                    "date": "2026-03-03T22:31:09.207813Z",
                    "number": "3",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (1).| CWES updated (1)."
                },
                {
                    "date": "2026-03-03T22:31:17.334882Z",
                    "number": "4",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-03T22:38:39.284320Z",
                    "number": "5",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (1).| References created (1).| CWES updated (1)."
                },
                {
                    "date": "2026-03-03T22:38:46.282100Z",
                    "number": "6",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-04T15:18:09.541912Z",
                    "number": "7",
                    "summary": "Source created.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-03-04T15:18:18.179472Z",
                    "number": "8",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-04T18:31:23.231033Z",
                    "number": "9",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (88).| Product Identifiers created (87).| References created (1).| CWES updated (1)."
                },
                {
                    "date": "2026-03-04T21:41:27.059553Z",
                    "number": "10",
                    "summary": "Unknown change."
                },
                {
                    "date": "2026-03-05T18:25:05.941616Z",
                    "number": "11",
                    "summary": "Products connected (1).| Product Identifiers created (1).| Exploits created (1)."
                },
                {
                    "date": "2026-03-05T18:25:09.637008Z",
                    "number": "12",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-06T20:32:05.869391Z",
                    "number": "13",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-12T09:54:18.652683Z",
                    "number": "14",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (76).| References created (3).| CWES updated (1)."
                },
                {
                    "date": "2026-03-12T09:54:33.560211Z",
                    "number": "15",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-20T09:42:48.838517Z",
                    "number": "16",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-03-20T09:42:51.699353Z",
                    "number": "17",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-27T13:51:23.086144Z",
                    "number": "18",
                    "summary": "NCSC Score updated."
                }
            ],
            "status": "interim",
            "version": "18"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<=2.9.8",
                                "product": {
                                    "name": "vers:unknown/<=2.9.8",
                                    "product_id": "CSAFPID-5585950",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:devcode:openstamanager:*:*:*:*:*:*:*:*"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "OpenSTAManager"
                    }
                ],
                "category": "vendor",
                "name": "Devcode"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.3.0",
                                "product": {
                                    "name": "vers:unknown/2.3.0",
                                    "product_id": "CSAFPID-5197969",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@2.3.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<=2.9.8",
                                "product": {
                                    "name": "vers:unknown/<=2.9.8",
                                    "product_id": "CSAFPID-5528647"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=0|<=2.9.8",
                                "product": {
                                    "name": "vers:unknown/>=0|<=2.9.8",
                                    "product_id": "CSAFPID-5507011"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.3",
                                "product": {
                                    "name": "vers:unknown/v2.3",
                                    "product_id": "CSAFPID-5197750"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.3-beta.1",
                                "product": {
                                    "name": "vers:unknown/v2.3-beta.1",
                                    "product_id": "CSAFPID-5197751"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.3-beta.2",
                                "product": {
                                    "name": "vers:unknown/v2.3-beta.2",
                                    "product_id": "CSAFPID-5197752"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.3.1",
                                "product": {
                                    "name": "vers:unknown/v2.3.1",
                                    "product_id": "CSAFPID-5197753"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4",
                                "product": {
                                    "name": "vers:unknown/v2.4",
                                    "product_id": "CSAFPID-5197754",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.1",
                                "product": {
                                    "name": "vers:unknown/v2.4.1",
                                    "product_id": "CSAFPID-5197755",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.10",
                                "product": {
                                    "name": "vers:unknown/v2.4.10",
                                    "product_id": "CSAFPID-5197756",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.10"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.11",
                                "product": {
                                    "name": "vers:unknown/v2.4.11",
                                    "product_id": "CSAFPID-5197757",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.11"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.12",
                                "product": {
                                    "name": "vers:unknown/v2.4.12",
                                    "product_id": "CSAFPID-5197758",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.12"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.13",
                                "product": {
                                    "name": "vers:unknown/v2.4.13",
                                    "product_id": "CSAFPID-5197759",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.13"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.14",
                                "product": {
                                    "name": "vers:unknown/v2.4.14",
                                    "product_id": "CSAFPID-5197760",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.14"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.15",
                                "product": {
                                    "name": "vers:unknown/v2.4.15",
                                    "product_id": "CSAFPID-5197761",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.15"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.16",
                                "product": {
                                    "name": "vers:unknown/v2.4.16",
                                    "product_id": "CSAFPID-5197762",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.16"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.17",
                                "product": {
                                    "name": "vers:unknown/v2.4.17",
                                    "product_id": "CSAFPID-5197763",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.17"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.17.1",
                                "product": {
                                    "name": "vers:unknown/v2.4.17.1",
                                    "product_id": "CSAFPID-5197970",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.17.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.18",
                                "product": {
                                    "name": "vers:unknown/v2.4.18",
                                    "product_id": "CSAFPID-5197764",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.18"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.19",
                                "product": {
                                    "name": "vers:unknown/v2.4.19",
                                    "product_id": "CSAFPID-5197765",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.19"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.2",
                                "product": {
                                    "name": "vers:unknown/v2.4.2",
                                    "product_id": "CSAFPID-5197766",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.20",
                                "product": {
                                    "name": "vers:unknown/v2.4.20",
                                    "product_id": "CSAFPID-5197767",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.20"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.21",
                                "product": {
                                    "name": "vers:unknown/v2.4.21",
                                    "product_id": "CSAFPID-5197768",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.21"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.22",
                                "product": {
                                    "name": "vers:unknown/v2.4.22",
                                    "product_id": "CSAFPID-5197769",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.22"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.23",
                                "product": {
                                    "name": "vers:unknown/v2.4.23",
                                    "product_id": "CSAFPID-5197770",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.23"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.24",
                                "product": {
                                    "name": "vers:unknown/v2.4.24",
                                    "product_id": "CSAFPID-3502394",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.24"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.25",
                                "product": {
                                    "name": "vers:unknown/v2.4.25",
                                    "product_id": "CSAFPID-3502395",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.25"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.26",
                                "product": {
                                    "name": "vers:unknown/v2.4.26",
                                    "product_id": "CSAFPID-3502396",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.26"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.27",
                                "product": {
                                    "name": "vers:unknown/v2.4.27",
                                    "product_id": "CSAFPID-3502397",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.27"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.28",
                                "product": {
                                    "name": "vers:unknown/v2.4.28",
                                    "product_id": "CSAFPID-3502398",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.28"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.29",
                                "product": {
                                    "name": "vers:unknown/v2.4.29",
                                    "product_id": "CSAFPID-3502399",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.29"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.3",
                                "product": {
                                    "name": "vers:unknown/v2.4.3",
                                    "product_id": "CSAFPID-5197771",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.3"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.30",
                                "product": {
                                    "name": "vers:unknown/v2.4.30",
                                    "product_id": "CSAFPID-3502400",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.30"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.31",
                                "product": {
                                    "name": "vers:unknown/v2.4.31",
                                    "product_id": "CSAFPID-3502401",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.31"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.32",
                                "product": {
                                    "name": "vers:unknown/v2.4.32",
                                    "product_id": "CSAFPID-3502402",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.32"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.33",
                                "product": {
                                    "name": "vers:unknown/v2.4.33",
                                    "product_id": "CSAFPID-3502403",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.33"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.34",
                                "product": {
                                    "name": "vers:unknown/v2.4.34",
                                    "product_id": "CSAFPID-3502404",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.34"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.35",
                                "product": {
                                    "name": "vers:unknown/v2.4.35",
                                    "product_id": "CSAFPID-3502405",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.35"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.36",
                                "product": {
                                    "name": "vers:unknown/v2.4.36",
                                    "product_id": "CSAFPID-3502406",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.36"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.37",
                                "product": {
                                    "name": "vers:unknown/v2.4.37",
                                    "product_id": "CSAFPID-3502407",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.37"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.38",
                                "product": {
                                    "name": "vers:unknown/v2.4.38",
                                    "product_id": "CSAFPID-3502408",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.38"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.39",
                                "product": {
                                    "name": "vers:unknown/v2.4.39",
                                    "product_id": "CSAFPID-3502409",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.39"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.4",
                                "product": {
                                    "name": "vers:unknown/v2.4.4",
                                    "product_id": "CSAFPID-5197772",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.4"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.40",
                                "product": {
                                    "name": "vers:unknown/v2.4.40",
                                    "product_id": "CSAFPID-3502410",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.40"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.41",
                                "product": {
                                    "name": "vers:unknown/v2.4.41",
                                    "product_id": "CSAFPID-3502411",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.41"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.42",
                                "product": {
                                    "name": "vers:unknown/v2.4.42",
                                    "product_id": "CSAFPID-3502412",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.42"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.43",
                                "product": {
                                    "name": "vers:unknown/v2.4.43",
                                    "product_id": "CSAFPID-3502413",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.43"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.44",
                                "product": {
                                    "name": "vers:unknown/v2.4.44",
                                    "product_id": "CSAFPID-3502414",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.44"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.45",
                                "product": {
                                    "name": "vers:unknown/v2.4.45",
                                    "product_id": "CSAFPID-3502415",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.45"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.46",
                                "product": {
                                    "name": "vers:unknown/v2.4.46",
                                    "product_id": "CSAFPID-3502416",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.46"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.47",
                                "product": {
                                    "name": "vers:unknown/v2.4.47",
                                    "product_id": "CSAFPID-3502417",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.47"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.48",
                                "product": {
                                    "name": "vers:unknown/v2.4.48",
                                    "product_id": "CSAFPID-5197773",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.48"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.49",
                                "product": {
                                    "name": "vers:unknown/v2.4.49",
                                    "product_id": "CSAFPID-5197774",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.49"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.5",
                                "product": {
                                    "name": "vers:unknown/v2.4.5",
                                    "product_id": "CSAFPID-5197775",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.5"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.50",
                                "product": {
                                    "name": "vers:unknown/v2.4.50",
                                    "product_id": "CSAFPID-5197776",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.50"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.51",
                                "product": {
                                    "name": "vers:unknown/v2.4.51",
                                    "product_id": "CSAFPID-5197777",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.51"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.52",
                                "product": {
                                    "name": "vers:unknown/v2.4.52",
                                    "product_id": "CSAFPID-5197778",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.52"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.53",
                                "product": {
                                    "name": "vers:unknown/v2.4.53",
                                    "product_id": "CSAFPID-5197779",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.53"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.54",
                                "product": {
                                    "name": "vers:unknown/v2.4.54",
                                    "product_id": "CSAFPID-5197780",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.54"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.6",
                                "product": {
                                    "name": "vers:unknown/v2.4.6",
                                    "product_id": "CSAFPID-5197781",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.6"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.7",
                                "product": {
                                    "name": "vers:unknown/v2.4.7",
                                    "product_id": "CSAFPID-5197782",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.7"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.8",
                                "product": {
                                    "name": "vers:unknown/v2.4.8",
                                    "product_id": "CSAFPID-5197783",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.8"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.9",
                                "product": {
                                    "name": "vers:unknown/v2.4.9",
                                    "product_id": "CSAFPID-5197784",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.9"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.5",
                                "product": {
                                    "name": "vers:unknown/v2.5",
                                    "product_id": "CSAFPID-5197785",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.5"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.5.1-beta",
                                "product": {
                                    "name": "vers:unknown/v2.5.1-beta",
                                    "product_id": "CSAFPID-5197786",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.5.1-beta"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.5.2-beta",
                                "product": {
                                    "name": "vers:unknown/v2.5.2-beta",
                                    "product_id": "CSAFPID-5197787",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.5.2-beta"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.5.3",
                                "product": {
                                    "name": "vers:unknown/v2.5.3",
                                    "product_id": "CSAFPID-5197788",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.5.3"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.5.4",
                                "product": {
                                    "name": "vers:unknown/v2.5.4",
                                    "product_id": "CSAFPID-5197789",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.5.4"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.5.5",
                                "product": {
                                    "name": "vers:unknown/v2.5.5",
                                    "product_id": "CSAFPID-5197790",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.5.5"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.5.6",
                                "product": {
                                    "name": "vers:unknown/v2.5.6",
                                    "product_id": "CSAFPID-5197971",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.5.6"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.5.7",
                                "product": {
                                    "name": "vers:unknown/v2.5.7",
                                    "product_id": "CSAFPID-5197972",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.5.7"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.6-beta",
                                "product": {
                                    "name": "vers:unknown/v2.6-beta",
                                    "product_id": "CSAFPID-5197973",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.6-beta"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.6.1",
                                "product": {
                                    "name": "vers:unknown/v2.6.1",
                                    "product_id": "CSAFPID-5197791",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.6.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.6.2",
                                "product": {
                                    "name": "vers:unknown/v2.6.2",
                                    "product_id": "CSAFPID-5197792",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.6.2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.7",
                                "product": {
                                    "name": "vers:unknown/v2.7",
                                    "product_id": "CSAFPID-5197974",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.7"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.7-beta",
                                "product": {
                                    "name": "vers:unknown/v2.7-beta",
                                    "product_id": "CSAFPID-5197975",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.7-beta"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.7.1",
                                "product": {
                                    "name": "vers:unknown/v2.7.1",
                                    "product_id": "CSAFPID-5197976",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.7.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.7.2",
                                "product": {
                                    "name": "vers:unknown/v2.7.2",
                                    "product_id": "CSAFPID-5197977",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.7.2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.7.3",
                                "product": {
                                    "name": "vers:unknown/v2.7.3",
                                    "product_id": "CSAFPID-5197978",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.7.3"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.8-beta",
                                "product": {
                                    "name": "vers:unknown/v2.8-beta",
                                    "product_id": "CSAFPID-5197979",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.8-beta"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.8.1",
                                "product": {
                                    "name": "vers:unknown/v2.8.1",
                                    "product_id": "CSAFPID-5197980",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.8.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.8.2",
                                "product": {
                                    "name": "vers:unknown/v2.8.2",
                                    "product_id": "CSAFPID-5197981",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.8.2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.8.3",
                                "product": {
                                    "name": "vers:unknown/v2.8.3",
                                    "product_id": "CSAFPID-5197982",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.8.3"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.9",
                                "product": {
                                    "name": "vers:unknown/v2.9",
                                    "product_id": "CSAFPID-5197793",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.9"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.9-beta",
                                "product": {
                                    "name": "vers:unknown/v2.9-beta",
                                    "product_id": "CSAFPID-5197794",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.9-beta"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.9.1",
                                "product": {
                                    "name": "vers:unknown/v2.9.1",
                                    "product_id": "CSAFPID-5197983",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.9.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.9.2",
                                "product": {
                                    "name": "vers:unknown/v2.9.2",
                                    "product_id": "CSAFPID-5197795",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.9.2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.9.3",
                                "product": {
                                    "name": "vers:unknown/v2.9.3",
                                    "product_id": "CSAFPID-5197796",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.9.3"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.9.4",
                                "product": {
                                    "name": "vers:unknown/v2.9.4",
                                    "product_id": "CSAFPID-5197797",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.9.4"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.9.5",
                                "product": {
                                    "name": "vers:unknown/v2.9.5",
                                    "product_id": "CSAFPID-5507007",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.9.5"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.9.6",
                                "product": {
                                    "name": "vers:unknown/v2.9.6",
                                    "product_id": "CSAFPID-5507008",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.9.6"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.9.7",
                                "product": {
                                    "name": "vers:unknown/v2.9.7",
                                    "product_id": "CSAFPID-5507009",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.9.7"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.9.8",
                                "product": {
                                    "name": "vers:unknown/v2.9.8",
                                    "product_id": "CSAFPID-5507010",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.9.8"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "openstamanager"
                    }
                ],
                "category": "vendor",
                "name": "devcode-it"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2026-27012",
            "cwe": {
                "id": "CWE-306",
                "name": "Missing Authentication for Critical Function"
            },
            "notes": [
                {
                    "category": "description",
                    "text": "### Summary\nA privilege escalation and authentication bypass vulnerability in OpenSTAManager allows any attacker to arbitrarily change a user's group (`idgruppo`) by directly calling `modules/utenti/actions.php`. This can promote an existing account (e.g. agent) into the Amministratori group as well as demote any user including existing administrators.\n\n### Details\n`modules/utenti/actions.php` is reachable directly via `http://<IP>:8080/modules/utenti/actions.php` and processes privileged information without requiring any authentication or authorization checks on fields like idgruppo. As a result, an attacker can submit a crafted POST request that updates the targets record and assigns it to the administrator group.\n\nThe file explicitly sets:\n```PHP\n$skip_permissions = true;\ninclude_once __DIR__.'/../../core.php';\n```\n`core.php` then invokes:\n\n```PHP\nPermissions::skip();\n```\nThus, disabling any authentication and permission enforcement. As a result, this file processes operations based on the `op` parameter in the POST request, not only `update_user`. Sensitive fields like `idgruppo` and others can be updated without verifying anything.\n\n### PoC\nA target username exists, such as \"agent\" with an ID of 4. No authentication or cookies are required. Send the following POST request via Burp Suite or similar:\n<img width=\"1094\" height=\"255\" alt=\"image\" src=\"https://github.com/user-attachments/assets/2e8cb148-1b5d-4e5c-9c73-05ed75d64188\" />\nThe target's group is updated in the database.\nVerify the changes in the database before and after the POST request:\n<img width=\"1053\" height=\"430\" alt=\"image\" src=\"https://github.com/user-attachments/assets/49f63ca0-8a04-4dd1-b27c-69699d2ce26f\" />\nChanges also visible in the administrator panel, they have been moved from the Agenti group to Amministratori.\n\n### Impact\nAn unauthenticated attacker can assign administrator privileges to existing users, modify group memberships, enable/disable accounts and other operations that are exposed in the file. This can lead to a full compromise of the application.",
                    "title": "github - https://github.com/advisories/GHSA-247v-7cw6-q57v"
                },
                {
                    "category": "description",
                    "text": "OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, a privilege escalation and authentication bypass vulnerability in OpenSTAManager allows any attacker to arbitrarily change a user's group (idgruppo) by directly calling modules/utenti/actions.php. This can promote an existing account (e.g. agent) into the Amministratori group as well as demote any user including existing administrators.",
                    "title": "nvd - https://nvd.nist.gov/vuln/detail/CVE-2026-27012"
                },
                {
                    "category": "description",
                    "text": "OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, a privilege escalation and authentication bypass vulnerability in OpenSTAManager allows any attacker to arbitrarily change a user's group (idgruppo) by directly calling modules/utenti/actions.php. This can promote an existing account (e.g. agent) into the Amministratori group as well as demote any user including existing administrators.",
                    "title": "cveprojectv5 - https://www.cve.org/CVERecord?id=CVE-2026-27012"
                },
                {
                    "category": "description",
                    "text": "### Summary\nA privilege escalation and authentication bypass vulnerability in OpenSTAManager allows any attacker to arbitrarily change a user's group (`idgruppo`) by directly calling `modules/utenti/actions.php`. This can promote an existing account (e.g. agent) into the Amministratori group as well as demote any user including existing administrators.\n\n### Details\n`modules/utenti/actions.php` is reachable directly via `http://<IP>:8080/modules/utenti/actions.php` and processes privileged information without requiring any authentication or authorization checks on fields like idgruppo. As a result, an attacker can submit a crafted POST request that updates the targets record and assigns it to the administrator group.\n\nThe file explicitly sets:\n```PHP\n$skip_permissions = true;\ninclude_once __DIR__.'/../../core.php';\n```\n`core.php` then invokes:\n\n```PHP\nPermissions::skip();\n```\nThus, disabling any authentication and permission enforcement. As a result, this file processes operations based on the `op` parameter in the POST request, not only `update_user`. Sensitive fields like `idgruppo` and others can be updated without verifying anything.\n\n### PoC\nA target username exists, such as \"agent\" with an ID of 4. No authentication or cookies are required. Send the following POST request via Burp Suite or similar:\n<img width=\"1094\" height=\"255\" alt=\"image\" src=\"https://github.com/user-attachments/assets/2e8cb148-1b5d-4e5c-9c73-05ed75d64188\" />\nThe target's group is updated in the database.\nVerify the changes in the database before and after the POST request:\n<img width=\"1053\" height=\"430\" alt=\"image\" src=\"https://github.com/user-attachments/assets/49f63ca0-8a04-4dd1-b27c-69699d2ce26f\" />\nChanges also visible in the administrator panel, they have been moved from the Agenti group to Amministratori.\n\n### Impact\nAn unauthenticated attacker can assign administrator privileges to existing users, modify group memberships, enable/disable accounts and other operations that are exposed in the file. This can lead to a full compromise of the application.",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Packagist%2FGHSA-247v-7cw6-q57v.json?alt=media"
                },
                {
                    "category": "description",
                    "text": "OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, a privilege escalation and authentication bypass vulnerability in OpenSTAManager allows any attacker to arbitrarily change a user's group (idgruppo) by directly calling modules/utenti/actions.php. This can promote an existing account (e.g. agent) into the Amministratori group as well as demote any user including existing administrators.",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/GIT%2FCVE-2026-27012.json?alt=media"
                },
                {
                    "category": "other",
                    "text": "0.0003",
                    "title": "EPSS"
                },
                {
                    "category": "other",
                    "text": "3.8",
                    "title": "NCSC Score"
                },
                {
                    "category": "other",
                    "text": "Is related to (a version of) an uncommon product, There is exploit data available from source Nvd, Exploit code publicly available",
                    "title": "NCSC Score top decreasing factors"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-5528647",
                    "CSAFPID-3502394",
                    "CSAFPID-3502395",
                    "CSAFPID-3502396",
                    "CSAFPID-3502397",
                    "CSAFPID-3502398",
                    "CSAFPID-3502399",
                    "CSAFPID-3502400",
                    "CSAFPID-3502401",
                    "CSAFPID-3502402",
                    "CSAFPID-3502403",
                    "CSAFPID-3502404",
                    "CSAFPID-3502405",
                    "CSAFPID-3502406",
                    "CSAFPID-3502407",
                    "CSAFPID-3502408",
                    "CSAFPID-3502409",
                    "CSAFPID-3502410",
                    "CSAFPID-3502411",
                    "CSAFPID-3502412",
                    "CSAFPID-3502413",
                    "CSAFPID-3502414",
                    "CSAFPID-3502415",
                    "CSAFPID-3502416",
                    "CSAFPID-3502417",
                    "CSAFPID-5197754",
                    "CSAFPID-5197755",
                    "CSAFPID-5197756",
                    "CSAFPID-5197757",
                    "CSAFPID-5197758",
                    "CSAFPID-5197759",
                    "CSAFPID-5197760",
                    "CSAFPID-5197761",
                    "CSAFPID-5197762",
                    "CSAFPID-5197763",
                    "CSAFPID-5197764",
                    "CSAFPID-5197765",
                    "CSAFPID-5197766",
                    "CSAFPID-5197767",
                    "CSAFPID-5197768",
                    "CSAFPID-5197769",
                    "CSAFPID-5197770",
                    "CSAFPID-5197771",
                    "CSAFPID-5197772",
                    "CSAFPID-5197773",
                    "CSAFPID-5197774",
                    "CSAFPID-5197775",
                    "CSAFPID-5197776",
                    "CSAFPID-5197777",
                    "CSAFPID-5197778",
                    "CSAFPID-5197779",
                    "CSAFPID-5197780",
                    "CSAFPID-5197781",
                    "CSAFPID-5197782",
                    "CSAFPID-5197783",
                    "CSAFPID-5197784",
                    "CSAFPID-5197785",
                    "CSAFPID-5197786",
                    "CSAFPID-5197787",
                    "CSAFPID-5197788",
                    "CSAFPID-5197789",
                    "CSAFPID-5197790",
                    "CSAFPID-5197791",
                    "CSAFPID-5197792",
                    "CSAFPID-5197793",
                    "CSAFPID-5197794",
                    "CSAFPID-5197795",
                    "CSAFPID-5197796",
                    "CSAFPID-5197797",
                    "CSAFPID-5197969",
                    "CSAFPID-5197970",
                    "CSAFPID-5197971",
                    "CSAFPID-5197972",
                    "CSAFPID-5197973",
                    "CSAFPID-5197974",
                    "CSAFPID-5197975",
                    "CSAFPID-5197976",
                    "CSAFPID-5197977",
                    "CSAFPID-5197978",
                    "CSAFPID-5197979",
                    "CSAFPID-5197980",
                    "CSAFPID-5197981",
                    "CSAFPID-5197982",
                    "CSAFPID-5197983",
                    "CSAFPID-5507007",
                    "CSAFPID-5507008",
                    "CSAFPID-5507009",
                    "CSAFPID-5507010",
                    "CSAFPID-5507011",
                    "CSAFPID-5585950",
                    "CSAFPID-5197750",
                    "CSAFPID-5197751",
                    "CSAFPID-5197752",
                    "CSAFPID-5197753"
                ]
            },
            "references": [
                {
                    "category": "external",
                    "summary": "Source - github",
                    "url": "https://github.com/advisories/GHSA-247v-7cw6-q57v"
                },
                {
                    "category": "external",
                    "summary": "Source raw - github",
                    "url": "https://api.github.com/advisories/GHSA-247v-7cw6-q57v"
                },
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27012"
                },
                {
                    "category": "external",
                    "summary": "Source raw - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-27012"
                },
                {
                    "category": "external",
                    "summary": "Source - cveprojectv5",
                    "url": "https://www.cve.org/CVERecord?id=CVE-2026-27012"
                },
                {
                    "category": "external",
                    "summary": "Source raw - cveprojectv5",
                    "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/27xxx/CVE-2026-27012.json"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?cve=CVE-2026-27012"
                },
                {
                    "category": "external",
                    "summary": "Source raw - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Packagist%2FGHSA-247v-7cw6-q57v.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/GIT%2FCVE-2026-27012.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; nvd; osv",
                    "url": "https://github.com/devcode-it/openstamanager/security/advisories/GHSA-247v-7cw6-q57v"
                },
                {
                    "category": "external",
                    "summary": "Reference - github",
                    "url": "https://github.com/advisories/GHSA-247v-7cw6-q57v"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/27xxx/CVE-2026-27012.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27012"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL"
                    },
                    "products": [
                        "CSAFPID-3502394",
                        "CSAFPID-3502395",
                        "CSAFPID-3502396",
                        "CSAFPID-3502397",
                        "CSAFPID-3502398",
                        "CSAFPID-3502399",
                        "CSAFPID-3502400",
                        "CSAFPID-3502401",
                        "CSAFPID-3502402",
                        "CSAFPID-3502403",
                        "CSAFPID-3502404",
                        "CSAFPID-3502405",
                        "CSAFPID-3502406",
                        "CSAFPID-3502407",
                        "CSAFPID-3502408",
                        "CSAFPID-3502409",
                        "CSAFPID-3502410",
                        "CSAFPID-3502411",
                        "CSAFPID-3502412",
                        "CSAFPID-3502413",
                        "CSAFPID-3502414",
                        "CSAFPID-3502415",
                        "CSAFPID-3502416",
                        "CSAFPID-3502417",
                        "CSAFPID-5197750",
                        "CSAFPID-5197751",
                        "CSAFPID-5197752",
                        "CSAFPID-5197753",
                        "CSAFPID-5197754",
                        "CSAFPID-5197755",
                        "CSAFPID-5197756",
                        "CSAFPID-5197757",
                        "CSAFPID-5197758",
                        "CSAFPID-5197759",
                        "CSAFPID-5197760",
                        "CSAFPID-5197761",
                        "CSAFPID-5197762",
                        "CSAFPID-5197763",
                        "CSAFPID-5197764",
                        "CSAFPID-5197765",
                        "CSAFPID-5197766",
                        "CSAFPID-5197767",
                        "CSAFPID-5197768",
                        "CSAFPID-5197769",
                        "CSAFPID-5197770",
                        "CSAFPID-5197771",
                        "CSAFPID-5197772",
                        "CSAFPID-5197773",
                        "CSAFPID-5197774",
                        "CSAFPID-5197775",
                        "CSAFPID-5197776",
                        "CSAFPID-5197777",
                        "CSAFPID-5197778",
                        "CSAFPID-5197779",
                        "CSAFPID-5197780",
                        "CSAFPID-5197781",
                        "CSAFPID-5197782",
                        "CSAFPID-5197783",
                        "CSAFPID-5197784",
                        "CSAFPID-5197785",
                        "CSAFPID-5197786",
                        "CSAFPID-5197787",
                        "CSAFPID-5197788",
                        "CSAFPID-5197789",
                        "CSAFPID-5197790",
                        "CSAFPID-5197791",
                        "CSAFPID-5197792",
                        "CSAFPID-5197793",
                        "CSAFPID-5197794",
                        "CSAFPID-5197795",
                        "CSAFPID-5197796",
                        "CSAFPID-5197797",
                        "CSAFPID-5197969",
                        "CSAFPID-5197970",
                        "CSAFPID-5197971",
                        "CSAFPID-5197972",
                        "CSAFPID-5197973",
                        "CSAFPID-5197974",
                        "CSAFPID-5197975",
                        "CSAFPID-5197976",
                        "CSAFPID-5197977",
                        "CSAFPID-5197978",
                        "CSAFPID-5197979",
                        "CSAFPID-5197980",
                        "CSAFPID-5197981",
                        "CSAFPID-5197982",
                        "CSAFPID-5197983",
                        "CSAFPID-5507007",
                        "CSAFPID-5507008",
                        "CSAFPID-5507009",
                        "CSAFPID-5507010",
                        "CSAFPID-5507011",
                        "CSAFPID-5528647",
                        "CSAFPID-5585950"
                    ]
                }
            ],
            "title": "CVE-2026-27012"
        }
    ]
}