CVE-2026-14753Disclosure

LOWCVSS 5.5 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A vulnerability was detected in mjperpinosa stumasy up to 327d1b0f2915ba79d7ef8ebb74553e987609d9be. This impacts an unknown function of the file /PHP/objects/notes of the component Note Handler/Assignment Handler. Performing a manipulation of the argument assignment_item_id results in authorization bypass. The attack can be initiated remotely. The exploit is now public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-285CWE-639

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-07-05); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-07-05: 2Mentions · 2026-07-06: 1PoC Mentioned / Linked · 2026-07-06: 1Patch / Workaround · 2026-07-06: 1Technical Details · 2026-07-06: 107-0507-06
Signal classification2 categories
Disclosure
266.7%
PoC
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-07-052
Disclosure2
2026-07-061
PoC1
Full discourse3 posts
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    PoC

    #CVE-2026-14753 - Authorization Bypass in mjperpinosa stumasy. Remote exploit public. #CVSS 7.3. No patch available. Restrict access to /PHP/objects/notes immediately. #CVEAlert #infosec #cybersecurity #developers #100daysofcode #devsecops #devops #redteam #blueteam #linux https://www.valtersit.com/cve/CVE-2026-14753/

    Post summary

    The tweet announces CVE‑2026‑14753, an Authorization Bypass with a publicly released remote exploit, advises limiting access as a workaround, but does not provide exploit code or evidence of active exploitation.

    0000078
    974 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-14753 A vulnerability was detected in mjperpinosa stumasy up to 327d1b0f2915ba79d7ef8ebb74553e987609d9be. This impacts an unknown function of the file /PHP/objects/notes of… https://www.cve.org/CVERecord?id=CVE-2026-14753 ----- Traducción: CVE-2026-14753 Se … http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑14753 and notes a potential vulnerability in an unknown function of /PHP/objects/notes, pointing readers to the official CVE record.

    0000034
    91 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-14753 A vulnerability was detected in mjperpinosa stumasy up to 327d1b0f2915ba79d7ef8ebb74553e987609d9be. This impacts an unknown function of the file /PHP/objects/notes of… https://www.cve.org/CVERecord?id=CVE-2026-14753

    Post summary

    A new CVE has been reported as impacting an unknown function in the /PHP/objects/notes file, but no further technical or mitigation details are supplied.

    00000979
    57.7K followersView on X

Explore more