SEPTEMBER 11, 2026
Live Feed
Back to database
Case File

CVE-2026-15752

HIGH · CVSS 7.3 EPSS 0.30% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-14 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

A vulnerability exists in the backend user endpoint of the zhinianboke xianyu-auto-reply application, allowing unauthorized access due to insufficient authorization checks. This flaw can be exploited remotely, posing a significant risk to users of the affected product. Organizations utilizing this application should prioritize applying the provided patch to mitigate potential security breaches.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-15752
Severity
HIGH
CVSS
7.3
EPSS
0.30%

Original NVD Description

A vulnerability was found in zhinianboke xianyu-auto-reply up to dcb445ad97816ad65299a7580ee0c8c8f929da84. Affected is an unknown function of the file /api/v1/users/ of the component Backend User Endpoint. Performing a manipulation results in missing authorization. The attack may be initiated remotely. The exploit has been made public and could be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The patch is named 19fc3282a1bb78a05c34945c088525d20e081cbd. Applying a patch is the recommended action to fix this issue.