CVE-2026-15753
CVE-2026-15753 is a medium-severity vulnerability with a CVSS 3.x base score of 5.4. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-650.
Key facts
- Severity: Medium (CVSS 3.x base score 5.4)
- CVSS v2: 5.5
- CVSS v4: 2.1
- EPSS exploit prediction: 0% (18th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-650
- Published:
- Last modified:
Description
A vulnerability was determined in zhinianboke xianyu-auto-reply on Server. Affected by this vulnerability is an unknown functionality of the file /api/v1/payment/withdraw/review?action=approve. Executing a manipulation can lead to trusting http permission methods on the server side. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. This patch is called 19fc3282a1bb78a05c34945c088525d20e081cbd. It is best practice to apply a patch to resolve this issue.
Frequently asked questions
- What is CVE-2026-15753?
- A vulnerability was determined in zhinianboke xianyu-auto-reply on Server. Affected by this vulnerability is an unknown functionality of the file /api/v1/payment/withdraw/review?action=approve. Executing a manipulation can lead to trusting http permission methods on the server side. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. This patch is called 19fc3282a1bb78a05c34945c088525d20e081cbd. It is best practice to apply a patch to resolve this issue.
- How severe is CVE-2026-15753?
- CVE-2026-15753 has a CVSS 3.x base score of 5.4, rated medium severity. It is exploitable over network with low attack complexity, requires low privileges and no user interaction. Impact on confidentiality is none, integrity low, and availability low.
- Is CVE-2026-15753 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (18th percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-15753?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-15753 published?
- CVE-2026-15753 was published on 2026-07-14 and last updated on 2026-07-15.
References
- https://github.com/zhinianboke/xianyu-auto-reply/
- https://github.com/zhinianboke/xianyu-auto-reply/commit/19fc3282a1bb78a05c34945c088525d20e081cbd
- https://github.com/zhinianboke/xianyu-auto-reply/issues/192
- https://vuldb.com/cve/CVE-2026-15753
- https://vuldb.com/submit/856719
- https://vuldb.com/vuln/378335
- https://vuldb.com/vuln/378335/cti
Other CWE-650 vulnerabilities
- CVE-2024-28787 — High (CVSS 8.7): IBM Security Verify Access 10.0.0 through 10.0.7 and IBM Application Gateway 20.01 through 24.03 could allow a remote…
- CVE-2025-21120 — High (CVSS 8.3): Dell Avamar, versions prior to 19.10 SP1 with patch 338904, contains a Trusting HTTP Permission Methods on the…
- CVE-2024-45098 — Medium (CVSS 6.8): IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user to bypass intended access restrictions and conduct resource…
- CVE-2026-42543 — Medium (CVSS 4.3): IRIS is a web collaborative platform that helps incident responders share technical details during investigations.…
- CVE-2024-45282 — Medium (CVSS 4.3): Fields which are in 'read only' state in Bank Statement Draft in Manage Bank Statements application, could be modified…
- CVE-2024-56339 — Low (CVSS 3.7): IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.7 could allow a…