Description
A security vulnerability has been detected in nxp-auto-goldvip gvip up to 1.4.0. Affected by this issue is the function SitewiseCustomFunction of the component Lambda Function Handler. Such manipulation leads to improper access controls. The attack can be launched remotely. Upgrading to version 1.15.0 can resolve this issue. Upgrading the affected component is advised. The project explains: "The reported IAM permission configuration is a known historical issue that was already addressed in 2024, beginning with GoldVIP version 1.13.0. The permissions were updated in subsequent releases, including version 1.15.0. In addition, we also sent a request to either update or deprecate the older release in the AWS SAR application repository."
Published: 2026-08-09
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper access control flaw in the SitewiseCustomFunction component of the Lambda Function Handler within nxp-auto-goldvip gvip. Attackers can exploit the misconfigured IAM permissions to invoke or modify the Lambda function remotely, potentially exposing or altering data that the function processes. This grants unauthorized users a level of privilege that should otherwise be protected.

Affected Systems

The flaw impacts nxp-auto-goldvip gvip versions up to 1.4.0, as documented in the project's release history. An upgrade to version 1.15.0 applies the corrected IAM permissions and deprecates older, vulnerable releases, thereby restoring proper access controls.

Risk and Exploitability

The CVSS score of 5.1 places this issue in the moderate severity range, and although EPSS data is not available, the description indicates the attack can be launched remotely, signifying a realistic exploitation potential. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed widespread exploitation, but the underlying access control weakness remains a concern for organizations that rely on this Lambda function.

Generated by OpenCVE AI on August 9, 2026 at 17:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade nxp-auto-goldvip gvip to at least version 1.15.0 to apply the corrected IAM permissions.
  • Reconfigure IAM roles for the Lambda function to implement least privilege and remove legacy permissions linked to older releases.
  • Disable or deprecate older GoldVIP releases in the AWS SAR application repository to prevent accidental usage.
  • Verify that the Lambda execution role no longer grants broader access than necessary and adjust if needed.
  • Monitor CloudTrail for unusual invocation patterns that may indicate attempts to abuse the Lambda function.

Generated by OpenCVE AI on August 9, 2026 at 17:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 10 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 09 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in nxp-auto-goldvip gvip up to 1.4.0. Affected by this issue is the function SitewiseCustomFunction of the component Lambda Function Handler. Such manipulation leads to improper access controls. The attack can be launched remotely. Upgrading to version 1.15.0 can resolve this issue. Upgrading the affected component is advised. The project explains: "The reported IAM permission configuration is a known historical issue that was already addressed in 2024, beginning with GoldVIP version 1.13.0. The permissions were updated in subsequent releases, including version 1.15.0. In addition, we also sent a request to either update or deprecate the older release in the AWS SAR application repository."
Title nxp-auto-goldvip gvip Lambda Function SitewiseCustomFunction access control
First Time appeared Nxp-auto-goldvip
Nxp-auto-goldvip gvip
Weaknesses CWE-266
CWE-284
CPEs cpe:2.3:a:nxp-auto-goldvip:gvip:*:*:*:*:*:*:*:*
Vendors & Products Nxp-auto-goldvip
Nxp-auto-goldvip gvip
References
Metrics cvssV2_0

{'score': 5.8, 'vector': 'AV:N/AC:L/Au:M/C:P/I:P/A:P/E:ND/RL:OF/RC:C'}

cvssV3_0

{'score': 4.7, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Nxp-auto-goldvip Gvip
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-10T21:12:01.087Z

Reserved: 2026-08-08T18:56:39.567Z

Link: CVE-2026-19359

cve-icon Vulnrichment

Updated: 2026-08-10T19:31:39.189Z

cve-icon NVD

Status : Deferred

Published: 2026-08-09T17:16:21.860

Modified: 2026-08-12T20:59:21.023

Link: CVE-2026-19359

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-09T20:30:03Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment

  • CWE-284

    Improper Access Control