No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 31 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 31 Aug 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw has been found in MegaEase EaseProbe up to 2.3.0. Affected is the function realIP of the file web/server.go of the component Middleware. This manipulation of the argument X-Forwarded-For/X-Real-IP/True-Client-IP causes improper access controls. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | MegaEase EaseProbe Middleware server.go realIP access control | |
| First Time appeared |
Megaease
Megaease easeprobe |
|
| Weaknesses | CWE-266 CWE-284 |
|
| CPEs | cpe:2.3:a:megaease:easeprobe:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Megaease
Megaease easeprobe |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-08-31T17:51:14.790Z
Reserved: 2026-08-31T05:22:27.257Z
Link: CVE-2026-82815
Updated: 2026-08-31T17:51:08.342Z
Status : Received
Published: 2026-08-31T18:17:24.280
Modified: 2026-08-31T18:17:24.280
Link: CVE-2026-82815
No data.
OpenCVE Enrichment
Updated: 2026-08-31T18:30:03Z