Description
A vulnerability was identified in a2ui-project a2ui 0.8/0.9/1.0. Impacted is an unknown function of the file model-processor.ts of the component Model Processor. The manipulation of the argument current[segment] leads to information disclosure. The attack may be initiated remotely. The identifier of the patch is 1b3bff234661ce922cbc3771be642b23ec9fd0fa. To fix this issue, it is recommended to deploy a patch.
Published: 2026-09-16
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

The vulnerability lies in an unprotected function within model-processor.ts. By manipulating the argument current[segment], an attacker can trigger the disclosure of sensitive information. The flaw is an information disclosure (CWE‑200) that also involves inadequate authorization controls (CWE‑284). Attackers can initiate the exploit remotely, although the exact remote entry point is not explicitly documented in the input.

Affected Systems

The affected software is a2ui-project a2ui versions 0.8, 0.9, and 1.0. These can be identified by the CPE a2ui-project:a2ui.* and represent the Model Processor component of the a2ui project.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate impact, while the EPSS score of less than 1% suggests a very low probability of exploitation in the current environment. The vulnerability is not listed in the CISA KEV catalog. Because the description states the attack may be initiated remotely, the likely attack vector is over the network to a vulnerable endpoint that processes the current[segment] argument.

Generated by OpenCVE AI on September 17, 2026 at 22:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Deploy the patch identified by commit 1b3bff234661ce922cbc3771be642b23ec9fd0fa to the Model Processor component.
  • Restart the a2ui services to ensure the updated code is loaded.
  • If the patch cannot be applied directly, upgrade a2ui to a newer supported version that contains the fix.
  • Consider temporarily restricting network access to the a2ui server during the remediation process to limit exposure.

Generated by OpenCVE AI on September 17, 2026 at 22:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in a2ui-project a2ui 0.8/0.9/1.0. Impacted is an unknown function of the file model-processor.ts of the component Model Processor. The manipulation of the argument current[segment] leads to information disclosure. The attack may be initiated remotely. The identifier of the patch is 1b3bff234661ce922cbc3771be642b23ec9fd0fa. To fix this issue, it is recommended to deploy a patch.
Title a2ui-project a2ui Model Processor model-processor.ts information disclosure
First Time appeared A2ui-project
A2ui-project a2ui
Weaknesses CWE-200
CWE-284
CPEs cpe:2.3:a:a2ui-project:a2ui:*:*:*:*:*:*:*:*
Vendors & Products A2ui-project
A2ui-project a2ui
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:P/I:N/A:N/E:ND/RL:OF/RC:C'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:X/RL:O/RC:C'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:X/RL:O/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X'}


Subscriptions

A2ui-project A2ui
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-18T17:38:54.087Z

Reserved: 2026-09-16T05:19:44.490Z

Link: CVE-2026-92357

cve-icon Vulnrichment

Updated: 2026-09-18T17:38:45.367Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T11:17:25.740

Modified: 2026-09-28T23:10:00.143

Link: CVE-2026-92357

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T23:00:13Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control