OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-51879

CRITICAL · CVSS 9.1 EPSS 0.15% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

DeepTutor version 1.4.0 is vulnerable to an authorization bypass due to a user-controlled object identifier in the TutorBotManager.write_bot_file function. This flaw allows remote attackers to enumerate bot IDs and overwrite whitelisted control files of other bots via the HTTP tutorbot file route, potentially compromising the integrity of the affected bots. Organizations using this version of DeepTutor should prioritize remediation to prevent unauthorized access and manipulation of bot configurations.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-51879
Severity
CRITICAL
CVSS
9.1
EPSS
0.15%

Original NVD Description

deeptutor 1.4.0 contains an authorization bypass through a user-controlled object identifier in TutorBotManager.write_bot_file. A remote caller can enumerate bot IDs and overwrite another bot's whitelisted control files through the HTTP tutorbot file route.