CVE-2026-1341Disclosure

MEDIUMCVSS 9.3 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Avation Light Engine Pro exposes its configuration and control interface without any authentication or access control.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-02-03); latest day: 1
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-02-03: 2Mentions · 2026-02-04: 1Mentions · 2026-02-05: 1Active Exploitation · 2026-02-05: 1Patch / Workaround · 2026-02-05: 1Technical Details · 2026-02-03: 2Technical Details · 2026-02-05: 102-0302-0402-05
Signal classification3 categories
Disclosure
250.0%
General
125.0%
Active Exploitation
125.0%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-02-032
Disclosure2
2026-02-041
General1
2026-02-051
Active Exploitation1
Full discourse4 posts
  • NerdieNews@NewsNerdie
    Active Exploitation

    Today's Top Cybersecurity News – February 05, 2026 1. Critical Metro4Shell RCE Vulnerability Actively Exploited in React Native CLI The Metro4Shell vulnerability (CVE-2025-11953) in the React Native Metro Development Server is being actively exploited by threat actors to execute arbitrary code remotely. This flaw allows attackers to deliver malicious payloads targeting developer systems on Windows and Linux, posing a significant risk to development environments. Sources: Bleepingcomputer, Crowdstrike, Cvefeed, Darkreading, Feedburner, Gbhackers, Infosecurity-Magazine, Krebsonsecurity, Securityaffairs, Securityweek https://thehackernews.com/2026/02/hackers-exploit-metro4shell-rce-flaw-in.html 2. CVE-2026-1341: Critical Missing Authentication in Avation Light Engine Pro Avation Light Engine Pro's configuration and control interface lacks any authentication or access control, allowing unauthorized users to potentially manipulate critical settings. This vulnerability poses a severe risk of unauthorized access and control over affected systems. Sources: Cvefeed, Gbhackers https://cvefeed.io/vuln/detail/CVE-2026-1341 3. Multiple Critical Vulnerabilities in n8n Workflow Automation Platform Allow RCE and Data Exposure Several severe vulnerabilities have been identified in the n8n open source workflow automation platform, including sandbox escapes, arbitrary file write and read, OS command injection, and stored XSS. These flaws allow authenticated users with workflow modification permissions to execute remote code, read sensitive files, and perform cross-site scripting attacks, potentially leading to full system compromise. Patches addressing these issues have been released in recent versions. Sources: Bleepingcomputer, Cvefeed, Feedburner, Infosecurity-Magazine https://cvefeed.io/vuln/detail/CVE-2026-25115 4. Multiple Critical Vulnerabilities Disclosed in Wireless Access Points Including ELECOM and Hikvision Several critical vulnerabilities have been disclosed affecting wireless access points from ELECOM, Hikvision, and WRC models. These include a stack-based buffer overflow, authenticated command execution, and OS command injection, potentially allowing arbitrary code or command execution by attackers. Immediate mitigation and patching are recommended to prevent exploitation. Sources: Cvefeed, Gbhackers https://cvefeed.io/vuln/detail/CVE-2026-24465 5. Critical XXE Vulnerability in Apache Syncope Console Enables Session Hijacking A critical XML External Entity (XXE) vulnerability (CVE-2026-23795) in Apache Syncope's Console component allows authenticated administrators to execute attacks that can extract sensitive data and hijack active user sessions. This flaw affects multiple versions and poses significant risks to identity and access management systems. Sources: Cvefeed, Gbhackers https://gbhackers.com/apache-syncope-vulnerability/ Stay sharp. Stay secure. #NerdieNews #InfoSec #CyberSecurity #TechNews #DataSecurity #CyberThreats

    Post summary

    The roundup reports several critical CVEs, notes that Metro4Shell is being actively exploited, and includes patch or mitigation information for multiple affected products.

    0001068
    54 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1341 Avation Light Engine Pro exposes its configuration and control interface without any authentication or access control. https://www.cve.org/CVERecord?id=CVE-2026-1341

    Post summary

    CVE-2026-1341 is disclosed as a flaw that exposes Avation Light Engine Pro’s configuration and control interface without authentication or access control.

    00010226
    56.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-1341 Unauthenticated Configuration Access in Avation Light Engine Pro https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1341

    Post summary

    The text merely lists CVE-2026-1341 with a brief title and a link, providing no detailed information about the vulnerability, exploits, or mitigations.

    0000038
    4.0K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-1341: Missing Authentication for Critic... Completely naked config interface on Avation Light Engine Pro hands attackers full control over critical lighting infras... https://zerodaysignal.com/vulnerability/CVE-2026-1341 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE-2026-1341, highlighting a missing authentication flaw in Avation Light Engine Pro that could grant attackers complete control over critical lighting systems, with no evidence yet of exploitation or remediation.

    0000065
    132 followersView on X

Explore more