DFIR Radar[verified]@DFIR_RadarExploit
NocoBase workflow engine suffers a critical VM sandbox escape (CVE-2026-34156) that permits authenticated users to achieve RCE as root; full exploit code is publicly available, and version 2.0.28 patches the issue.
TL;DR CTF with Onurcan[verified]@CtfWithOGPatch
The vendor quickly acknowledged the issue, issued a patch in version 2.0.28, and the CVE is now resolved.
ANONHAVEN[verified]@anonhaven_comPatch
The post reports CVE-2026-34156, a CVSS 10.0 sandbox escape leading to root RCE in NocoBase, and notes that the issue was patched in version 2.0.28; no active exploitation or PoC details are provided.
TL;DR CTF with Onurcan[verified]@CtfWithOGExploit
A detailed technical writeup for CVE-2026-34156 is presented, including full methodology, enumeration phases, escape vectors, and a reverse shell demo, demonstrating a functional exploit.
ANONHAVEN[verified]@anonhaven_comActive Exploitation
The post discloses that CVE-2026-34156, a sandbox escape causing RCE in ocobase, is actively being exploited, includes a PoC and exploit code, and cites a vendor patch.
Gray Hats@the_yellow_fallPatch
The post announces a critical RCE vulnerability in NocoBase (CVE‑2026‑34156) and urges users to update to version 2.0.28 to apply the patch.
pdnuclei-bot@pdnuclei_botDisclosure
The tweet announces CVE-2026-34156 as a critical NocoBase vulnerability that allows remote code execution via VM sandbox escape, but provides no proof‑of‑concept, exploit code, active exploitation report or patch details.
Ashraf Zaryouh@0xBlackashPoC
A critical RCE in NocoBase (CVE-2026-34156) is disclosed with a PoC and Nuclei template, and users are urged to upgrade to version 2.0.28 or later.