CVE detail
CVE-2026-19928
A vulnerability was determined in OpenBoxes up to 0.9.7. This affects the function needManager of the file grails-app/controllers/org/pih/warehouse/RoleInterceptor.groovy of the component Role Interceptor. Executing a manipulation can lead to improper privilege management. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. Upgrading to version 0.9.8-hotfix1 and 0.9.8 mitigates this issue. This patch is called 788cace0af816aa972a713a4631c57f16f895e6b. Upgrading the affected component is recommended.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 24.0 · diversity 8.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 10
- within the 30d window
- Peak daily
- 10
- highest bucket
Evidence
Source links by recency
10 source links · newest first
- https://vuldb.com/vuln/390179/ctivuldb.com
No excerpt available.
Exploitvuldb.comAug 16, 2026, 3:16 AM - https://vuldb.com/vuln/390179vuldb.com
No excerpt available.
Exploitvuldb.comAug 16, 2026, 3:16 AM - https://vuldb.com/submit/871981vuldb.com
No excerpt available.
Exploitvuldb.comAug 16, 2026, 3:16 AM - https://vuldb.com/cve/CVE-2026-19928vuldb.com
No excerpt available.
Exploitvuldb.comAug 16, 2026, 3:16 AM No excerpt available.
Exploitgithub.comAug 16, 2026, 3:16 AMNo excerpt available.
Exploitgithub.comAug 16, 2026, 3:16 AMNo excerpt available.
Exploitgithub.comAug 16, 2026, 3:16 AMNo excerpt available.
Exploitgithub.comAug 16, 2026, 3:16 AM- https://github.com/OpenBoxes/OpenBoxes/github.com
No excerpt available.
Exploitgithub.comAug 16, 2026, 3:16 AM No excerpt available.
Exploitgist.github.comAug 16, 2026, 3:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-19381CVSS 7.1 · High
A security flaw has been discovered in Kingston FURY CTRL RGB Control Software 2.0.65.0. The impacted element is an unknown function in the library NTIOLib_KSFX.sys of the compone…
- CVE-2026-19360CVSS 5.1 · Medium
A vulnerability was detected in wongcyrus ExcelLexBot up to 0.0.3. This affects the function ExcelLexBotS3TriggerFunction of the component Lambda Function Handler. Performing a ma…
- CVE-2026-19189CVSS 7.1 · High
A security flaw has been discovered in Power Sofware PowerISO 9.3.0.0. Affected by this issue is some unknown functionality in the library C:\Windows\System32\drivers\scdemu.sys o…
- CVE-2026-19007CVSS 2.1 · Low
A vulnerability was determined in mf-yang openclaw-cn up to 0.2.1. This vulnerability affects the function isApprovedElevatedSender of the file src/auto-reply/reply/reply-elevated…
- CVE-2026-19005CVSS 2.1 · Low
A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. Affected is the function handleCreateAgent of the file src/modules/agent-to-agent/create-agent.ts of the component…
- CVE-2026-18606CVSS 7.1 · High
A weakness has been identified in Razer RzUpdateService 1.10.14.0. Affected by this vulnerability is an unknown functionality of the file C:\Program Files (x86)\Razer\RzUpdateEngi…