Description
A vulnerability was detected in wongcyrus ExcelLexBot up to 0.0.3. This affects the function ExcelLexBotS3TriggerFunction of the component Lambda Function Handler. Performing a manipulation results in improper privilege management. The attack may be initiated remotely. The vendor was contacted early about this disclosure but did not respond in any way. This vulnerability only affects products that are no longer supported by the maintainer.
Published: 2026-08-09
Score: 5.1 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The ExcelLexBotS3TriggerFunction in wongcyrus ExcelLexBot allows manipulation that leads to improper privilege management, enabling an attacker to elevate privileges or gain unauthorized access. The CVE notes that the attack may be initiated remotely, implying exploitation through an S3 event trigger or direct API call. With elevated rights, an adversary could read, modify, or delete data, or disrupt services for accounts using the function.

Affected Systems

Versions of wongcyrus ExcelLexBot up to 0.0.3 are vulnerable. These releases are no longer supported by the maintainer, increasing the risk of unpatched exploits. The flaw resides in the Lambda function handler that processes S3 trigger events.

Risk and Exploitability

The CVSS score of 5.1 reflects moderate severity. EPSS data is not available, so known exploitation frequency remains unknown. The vulnerability is not listed in CISA KEV, indicating no confirmed widespread exploitation to date. However, because the flaw permits remote privilege escalation and the Lambda function may run with broad IAM permissions, organizations should treat this as a significant risk and address it promptly.

Generated by OpenCVE AI on August 9, 2026 at 18:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade ExcelLexBot to the latest supported version or replace the component with an actively maintained alternative
  • Remove or disable the ExcelLexBotS3TriggerFunction if its functionality is not required, or restrict its operation to trusted sources only
  • Tighten IAM permissions on the Lambda function to the minimum privileges necessary for S3 event processing
  • Monitor CloudTrail logs for unauthorized activity related to the Lambda function

Generated by OpenCVE AI on August 9, 2026 at 18:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 09 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in wongcyrus ExcelLexBot up to 0.0.3. This affects the function ExcelLexBotS3TriggerFunction of the component Lambda Function Handler. Performing a manipulation results in improper privilege management. The attack may be initiated remotely. The vendor was contacted early about this disclosure but did not respond in any way. This vulnerability only affects products that are no longer supported by the maintainer.
Title wongcyrus ExcelLexBot Lambda Function ExcelLexBotS3TriggerFunction privileges management
First Time appeared Wongcyrus
Wongcyrus excellexbot
Weaknesses CWE-266
CWE-269
CPEs cpe:2.3:a:wongcyrus:excellexbot:*:*:*:*:*:*:*:*
Vendors & Products Wongcyrus
Wongcyrus excellexbot
References
Metrics cvssV2_0

{'score': 5.8, 'vector': 'AV:N/AC:L/Au:M/C:P/I:P/A:P/E:ND/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.7, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R'}

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Wongcyrus Excellexbot
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-09T17:00:08.191Z

Reserved: 2026-08-08T18:58:56.459Z

Link: CVE-2026-19360

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-09T18:30:04Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment

  • CWE-269

    Improper Privilege Management