
CVE-2026-30994 Incorrect access control in the config.php component of Slah v1.5.0 and below allows unauthenticated attackers to access sensitive information, including active sessi… https://www.cve.org/CVERecord?id=CVE-2026-30994
Post summary
The snippet announces a new CVE, detailing an access‑control flaw in Slah’s config.php that permits unauthenticated info disclosure, but provides no further exploits, mitigation guidance, or evidence of live attacks.

