AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-15141

MEDIUM · CVSS 5.3 EPSS 0.12% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The vulnerability exists in the web interface of certain devices that inadequately validate the HTTP referrer header, allowing requests with an empty or missing Referer value to be processed. This flaw can be exploited by an adjacent attacker to access sensitive device configuration details. Organizations using affected devices should prioritize remediation to protect against potential information disclosure risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-15141
Severity
MEDIUM
CVSS
5.3
EPSS
0.12%

Original NVD Description

The web interface of the affected device relies on the HTTP referrer header as part of request validation.  Requests containing empty Referer value, or omitting the Referer header entirely, may be accepted and processed due to insufficient validation logic. Successful exploitation may allow an adjacent attacker with access to the web management interface to obtain device configuration details and other sensitive information.