Vulnerability Description
A vulnerability was found in zhinianboke xianyu-auto-reply up to dcb445ad97816ad65299a7580ee0c8c8f929da84. Affected is an unknown function of the file /api/v1/users/ of the component Backend User Endpoint. Performing a manipulation results in missing authorization. The attack may be initiated remotely. The exploit has been made public and could be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The patch is named 19fc3282a1bb78a05c34945c088525d20e081cbd. Applying a patch is the recommended action to fix this issue.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/zhinianboke/xianyu-auto-reply/
- https://github.com/zhinianboke/xianyu-auto-reply/commit/19fc3282a1bb78a05c34945c
- https://github.com/zhinianboke/xianyu-auto-reply/issues/192
- https://vuldb.com/cve/CVE-2026-15752
- https://vuldb.com/submit/856716
- https://vuldb.com/vuln/378334
- https://vuldb.com/vuln/378334/cti
FAQ
What is CVE-2026-15752?
CVE-2026-15752 is a vulnerability with a CVSS score of 7.3 (HIGH). A vulnerability was found in zhinianboke xianyu-auto-reply up to dcb445ad97816ad65299a7580ee0c8c8f929da84. Affected is an unknown function of the file /api/v1/users/ of the component Backend User Endp...
How severe is CVE-2026-15752?
CVE-2026-15752 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-15752?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.