CVE-2026-0397 — When the internal webserver is enabled (default is disabled), an attacker might be able to trick an administrator logged to the dashboard into visiting a malicious website and extract information abou — CVE Database · The Intelligence Room