CVE-2026-15752
HIGHzhinianboke xianyu-auto-reply Backend User Endpoint users authorization
Title source: cnaDescription
A vulnerability was found in zhinianboke xianyu-auto-reply up to dcb445ad97816ad65299a7580ee0c8c8f929da84. Affected is an unknown function of the file /api/v1/users/ of the component Backend User Endpoint. Performing a manipulation results in missing authorization. The attack may be initiated remotely. The exploit has been made public and could be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The patch is named 19fc3282a1bb78a05c34945c088525d20e081cbd. Applying a patch is the recommended action to fix this issue.
References (7)
Core 7
Core References
Vdb Entry vdb-entry
VDB-378334 | zhinianboke xianyu-auto-reply Backend User Endpoint users authorization
https://vuldb.com/vuln/378334
Signature, Permissions Required signature
permissions-required
VDB-378334 | CTI Indicators (IOB, IOC, IOA)
https://vuldb.com/vuln/378334/cti
Third Party Advisory third-party-advisory
CVE-2026-15752 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-15752
Third Party Advisory third-party-advisory
Submit #856716 | zhinianboke xianyu-auto-reply main branch at or before commit 04580d6490b4731d0055f29736930d8cc59b60d6 CWE-862 Missing Authorization
https://vuldb.com/submit/856716
Exploit exploit
issue-tracking
https://github.com/zhinianboke/xianyu-auto-reply/issues/192
Patch patch
https://github.com/zhinianboke/xianyu-auto-reply/commit/19fc3282a1bb78a05c34945c088525d20e081cbd
Product product
https://github.com/zhinianboke/xianyu-auto-reply/
Scores
CVSS v3
7.3
EPSS
0.0030
EPSS Percentile
22.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-862
CWE-863
Status
published
Products (1)
zhinianboke/xianyu-auto-reply
dcb445ad97816ad65299a7580ee0c8c8f929da84
Published
Jul 14, 2026
Tracked Since
Jul 15, 2026