AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-19359

MEDIUM · CVSS 4.7 EPSS 0.36% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-09 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The vulnerability affects the nxp-auto-goldvip gvip up to version 1.4.0, specifically in the SitewiseCustomFunction of the Lambda Function Handler, leading to improper access controls that can be exploited remotely. Organizations utilizing this component should prioritize upgrading to version 1.15.0 or later to mitigate potential security risks. This issue is particularly relevant for teams managing AWS Lambda functions and those responsible for IAM permission configurations.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-19359
Severity
MEDIUM
CVSS
4.7
EPSS
0.36%

Original NVD Description

A security vulnerability has been detected in nxp-auto-goldvip gvip up to 1.4.0. Affected by this issue is the function SitewiseCustomFunction of the component Lambda Function Handler. Such manipulation leads to improper access controls. The attack can be launched remotely. Upgrading to version 1.15.0 can resolve this issue. Upgrading the affected component is advised. The project explains: "The reported IAM permission configuration is a known historical issue that was already addressed in 2024, beginning with GoldVIP version 1.13.0. The permissions were updated in subsequent releases, including version 1.15.0. In addition, we also sent a request to either update or deprecate the older release in the AWS SAR application repository."