SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-75928

MEDIUM · CVSS 5.3 EPSS 0.39%

Source: NVD + CISA KEV + EPSS · Published 2026-08-21 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Brushfire platform's video content streaming application exposes sensitive database path information in user requests, enabling remote, unauthenticated attackers to potentially access user data. This vulnerability poses a medium risk, particularly for organizations utilizing the Brushfire platform for streaming services. Users of this platform should prioritize applying the fix released in February 2026 to mitigate the risk of unauthorized data exposure.

CVE
CVE-2026-75928
Severity
MEDIUM
CVSS
5.3
EPSS
0.39%

Original NVD Description

The Brushfire platform's video content streaming application (https://online.brushfire.com) exposes database path in requests to users, allowing a remote, unauthenticated attacker to read information about other users. Fixed February 2026.