CVE-2026-11970
This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint SafariExtension and bypass DLP protection in F1E Mac OS before v26.04.5758.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.8
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
- EPSS probability
- 0.12%
- CWE
- CWE-754
- Published
- 2026-08-13
- Last modified
- 2026-08-13
Affected products
- Forcepoint F1E mac
Weakness type
Related vulnerabilities
- CVE-2026-87012 — Open WebUI: Any authenticated user can suppress calendar alerts instance-wide via a non-numeric alert value
- CVE-2026-87656 — Improper state validation in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed a remote...
- CVE-2026-87532 — Improper state validation in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed a remote...
- CVE-2026-87548 — Improper state validation in Installer in Google Chrome prior to 153.0.8010.36 allowed a remote...
- CVE-2026-87645 — Improper state validation in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed a remote...
- CVE-2026-73314 — XenForo < 2.3.13 Signature Verification Bypass via PayPal REST Webhook
- CVE-2026-85014 — undici vulnerable to Denial of Service via WebSocketStream unclean close
- CVE-2026-55484 — ALOS HTTP: Unauthenticated remote DoS: malformed path starting with "?" triggers out-of-bounds panic in sanitizeRequestPath, crashing entire server