CVE-2026-19360Disclosure

LOWCVSS 5.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was detected in wongcyrus ExcelLexBot up to 0.0.3. This affects the function ExcelLexBotS3TriggerFunction of the component Lambda Function Handler. Performing a manipulation results in improper privilege management. The attack may be initiated remotely. The vendor was contacted early about this disclosure but did not respond in any way. This vulnerability only affects products that are no longer supported by the maintainer.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-266CWE-269

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-08: 1Technical Details · 2026-08-08: 108-08
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • CyberSignal | Cybersecurity News@XQOPTRX
    Disclosure

    🤖 ExcelLexBot Lambda privileges flaw disclosed CVE-2026-19360 affects ExcelLexBot through 0.0.3. The issue involves privilege management in the project's ExcelLexBotS3TriggerFunction Lambda component. 📅 Disclosed: August 8. 🔎 Source: CVE/Vulnerability feed via YANAC. #AWS #CloudSecurity #CVE #CyberSecurity

    Post summary

    A CVE (CVE-2026-19360) affecting ExcelLexBot up to version 0.0.3 has been disclosed, highlighting a privilege management flaw in the ExcelLexBotS3TriggerFunction Lambda component.

    0000051
    34 followersView on X

Explore more