Description
A vulnerability was found in zhinianboke xianyu-auto-reply up to dcb445ad97816ad65299a7580ee0c8c8f929da84. Affected is an unknown function of the file /api/v1/users/ of the component Backend User Endpoint. Performing a manipulation results in missing authorization. The attack may be initiated remotely. The exploit has been made public and could be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The patch is named 19fc3282a1bb78a05c34945c088525d20e081cbd. Applying a patch is the recommended action to fix this issue.
Published: 2026-07-14
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability manifests as an authorization bypass on the /api/v1/users/ endpoint of the zhinianboke xianyu-auto-reply backend. An attacker may manipulate a request to that endpoint, allowing read or modification of user data without the proper authentication and role checks. The weakness is captured by CWE-862 (Missing Authorization) and CWE-863 (Missing Role‑Based Access Control). The result is unauthorized access to backend functionality and potentially compromising all user accounts.

Affected Systems

Affected versions cover any zhinianboke xianyu-auto-reply deployment built from source before the commit 19fc3282a1bb78a05c34945c088525d20e081cbd. As the project follows a rolling release model, specific version numbers are not given, but any instance running code prior to that patch is vulnerable.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate severity, while an EPSS score of less than 1% suggests low likelihood of current exploitation in the wild. The flaw is not listed in the CISA KEV catalog. However, the public release of the exploit and the ability to attain unauthorized access remotely mean that administrators should treat this as a moderate to high risk until the patch is applied.

Generated by OpenCVE AI on July 31, 2026 at 04:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the patch identified by commit 19fc3282a1bb78a05c34945c088525d20e081cbd to a release built from sources after that commit, ensuring the authorization checks are restored.
  • If the patch cannot be applied immediately, restrict or remove external access to the /api/v1/users/ endpoint until the offending code is fixed.
  • Monitor traffic and logs for suspicious requests to /api/v1/users/ and investigate any anomalies to detect potential exploitation attempts.

Generated by OpenCVE AI on July 31, 2026 at 04:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in zhinianboke xianyu-auto-reply up to dcb445ad97816ad65299a7580ee0c8c8f929da84. Affected is an unknown function of the file /api/v1/users/ of the component Backend User Endpoint. Performing a manipulation results in missing authorization. The attack may be initiated remotely. The exploit has been made public and could be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The patch is named 19fc3282a1bb78a05c34945c088525d20e081cbd. Applying a patch is the recommended action to fix this issue.
Title zhinianboke xianyu-auto-reply Backend User Endpoint users authorization
First Time appeared Zhinianboke
Zhinianboke xianyu-auto-reply
Weaknesses CWE-862
CWE-863
CPEs cpe:2.3:a:zhinianboke:xianyu-auto-reply:*:*:*:*:*:*:*:*
Vendors & Products Zhinianboke
Zhinianboke xianyu-auto-reply
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Zhinianboke Xianyu-auto-reply
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-07-15T12:40:30.487Z

Reserved: 2026-07-14T15:51:25.852Z

Link: CVE-2026-15752

cve-icon Vulnrichment

Updated: 2026-07-15T12:40:24.224Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T04:30:03Z

Weaknesses