CVE-2024-50619Disclosure(cipplanner / cipace)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch cipplanner cipace systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Vulnerabilities in the My Account and User Management components in CIPPlanner CIPAce before 9.17 allows attackers to escalate their access levels. A low-privileged authenticated user can gain access to other people's accounts by tampering with the client's user id to change their account information. A low-privileged authenticated user can elevate his or her system privileges by modifying the information of a user role that is disabled in the client.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cipace

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 1 mentions (2026-02-11); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
cipace

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-11: 1Mentions · 2026-02-13: 1Mentions · 2026-02-18: 1Patch / Workaround · 2026-02-13: 1Technical Details · 2026-02-11: 1Technical Details · 2026-02-13: 1Technical Details · 2026-02-18: 102-1102-1302-18
Signal classification1 categories
Disclosure
3100.0%
Referenced assets7 URLs
Full discourse3 posts
  • NerdieNews@NewsNerdie
    Disclosure

    Today's Top Cybersecurity News – February 13, 2026 1. Critical WPvivid Backup Flaw (CVSS 9.8) Exposes 800K WordPress Sites A critical vulnerability (CVE-2026-1357) in the WPvivid Backup plugin affects over 800,000 WordPress sites, potentially exposing sensitive backup data. This flaw poses a significant risk of data compromise and site integrity loss if exploited. Sources: Bleepingcomputer, Cvefeed, Darkreading, Feedburner, Gbhackers, Infosecurity-Magazine, Intel471, Malwarebytes, Mandiant, Proofpoint, Securityweek, Therecord https://securityonline.info/null-byte-nightmare-critical-wpvivid-backup-flaw-cvss-9-8-exposes-800k-wordpress-sites/ 2. Critical SandboxJS Vulnerability (CVE-2026-25881) Enables Host Takeover A critical flaw in SandboxJS allows attackers to escape the sandbox environment and execute malicious code on the host system. This vulnerability poses a severe risk to applications relying on SandboxJS for secure JavaScript execution. Sources: Cvefeed, Microsoft https://securityonline.info/sandbox-breakout-critical-sandboxjs-flaw-cve-2026-25881-allows-host-takeover/ 3. Multiple High and Critical Vulnerabilities Including Authentication Bypass, Buffer Overflows, and Path Traversal A series of critical and high-severity vulnerabilities have been disclosed affecting various software products including PRO-7070, OwnCloud, SpotAuditor, and others. These vulnerabilities enable attackers to bypass authentication, execute arbitrary code via buffer overflows and stack overflows, perform path traversal to access sensitive files, and disclose usernames, posing significant risks to affected systems. Immediate patching and mitigation are recommended to prevent unauthorized access and potential system compromise. Sources: Cvefeed https://cvefeed.io/vuln/detail/CVE-2019-25335 4. Multiple Critical Vulnerabilities in CIPPlanner CIPAce Allow Privilege Escalation and Arbitrary File Access CIPPlanner CIPAce versions before 9.17 contain multiple severe vulnerabilities including account privilege escalation, unauthorized file download, and arbitrary file upload of executable files. These flaws enable low-privileged authenticated users to escalate privileges, access unauthorized files, and potentially execute malicious code, posing significant security risks. Sources: Cvefeed, Feedburner, Securityaffairs https://cvefeed.io/vuln/detail/CVE-2024-50619 5. Critical Authentication Bypass Vulnerabilities Found in ZLAN5143D Devices Two critical vulnerabilities (CVE-2026-25084 and CVE-2026-24789) affect ZLAN5143D devices, allowing attackers to bypass authentication and remotely change device passwords via unprotected internal URLs and API endpoints. These flaws expose devices to unauthorized access and control, posing significant security risks. Sources: Cvefeed https://cvefeed.io/vuln/detail/CVE-2026-25084 Stay sharp. Stay secure. #NerdieNews #InfoSec #CyberSecurity #TechNews #DataSecurity #CyberThreats

    Post summary

    The piece highlights several newly disclosed high‑severity CVEs across WordPress plugins, JavaScript sandbox, and various software, detailing their technical impact and urging immediate patching, but it does not provide PoCs, exploit code, or evidence of active exploitation.

    0001056
    54 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2024-50619: HIGH] Security flaws in CIPPlanner CIPAce before 9.17 can be exploited to escalate access levels. Attackers can manipulate user IDs & disabled user roles to gain unauthorized privileges. #cy...#cve,CVE-2024-50619,#cybersecurity https://cvefind.com/CVE-2024-50619

    Post summary

    CIPPlanner CIPAce versions before 9.17 contain a high‑severity privilege escalation flaw that lets attackers manipulate user IDs and disabled user roles to gain unauthorized access.

    0000061
    578 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2024-50619 Vulnerabilities in the My Account and User Management components in CIPPlanner CIPAce before 9.17 allows attackers to escalate their access levels. A low-privileged a… https://www.cve.org/CVERecord?id=CVE-2024-50619

    Post summary

    The CVE describes a privilege escalation flaw in CIPPlanner CIPAce affecting the My Account and User Management components, with no evidence of a PoC, exploit code, active exploitation, or patch details.

    00000266
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcipplannercipace---

Explore more