CVE-2026-15752

HIGH

zhinianboke xianyu-auto-reply Backend User Endpoint users authorization

Title source: cna
STIX 2.1

Description

A vulnerability was found in zhinianboke xianyu-auto-reply up to dcb445ad97816ad65299a7580ee0c8c8f929da84. Affected is an unknown function of the file /api/v1/users/ of the component Backend User Endpoint. Performing a manipulation results in missing authorization. The attack may be initiated remotely. The exploit has been made public and could be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The patch is named 19fc3282a1bb78a05c34945c088525d20e081cbd. Applying a patch is the recommended action to fix this issue.

References (7)

Core 7
Core References
Vdb Entry vdb-entry
VDB-378334 | zhinianboke xianyu-auto-reply Backend User Endpoint users authorization
https://vuldb.com/vuln/378334
Signature, Permissions Required signature permissions-required
VDB-378334 | CTI Indicators (IOB, IOC, IOA)
https://vuldb.com/vuln/378334/cti
Third Party Advisory third-party-advisory
CVE-2026-15752 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-15752
Third Party Advisory third-party-advisory
Submit #856716 | zhinianboke xianyu-auto-reply main branch at or before commit 04580d6490b4731d0055f29736930d8cc59b60d6 CWE-862 Missing Authorization
https://vuldb.com/submit/856716

Scores

CVSS v3 7.3
EPSS 0.0030
EPSS Percentile 22.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-862 CWE-863
Status published
Products (1)
zhinianboke/xianyu-auto-reply dcb445ad97816ad65299a7580ee0c8c8f929da84
Published Jul 14, 2026
Tracked Since Jul 15, 2026