SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-15699

MEDIUM · CVSS 6.3 EPSS 0.26% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-14 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

The vulnerability affects the spencermountain compromise up to version 14.15.1, specifically within the nlp.extend function in the Public Root API, where improper control over the plugin argument allows for unauthorized modifications of object prototype attributes. This could lead to remote exploitation, making it critical for users of the affected product to prioritize applying the available patch to mitigate potential security risks. Organizations utilizing this software should act swiftly to ensure their systems are secured against this publicly exploitable vulnerability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-15699
Severity
MEDIUM
CVSS
6.3
EPSS
0.26%

Original NVD Description

A vulnerability was identified in spencermountain compromise up to 14.15.1. Affected is the function nlp.extend of the file src/API/extend.js of the component Public Root API. The manipulation of the argument plugin leads to improperly controlled modification of object prototype attributes. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The identifier of the patch is b4644ab7179700df0607521f61c1ee9b5f78d89d. Applying a patch is the recommended action to fix this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.