CVE-2026-22199Disclosure(gvectors / wpdiscuz)

LOWCVSS 8.7 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Voltronic Power SNMP Web Pro version 1.1 contains a pre-authentication path traversal vulnerability in the upload.cgi endpoint that allows unauthenticated attackers to read arbitrary files on the device filesystem by supplying directory traversal sequences in the params parameter. Attackers can exploit this vulnerability to disclose sensitive files such as password hashes, which can be cracked offline to obtain root-level access and enable full system compromise.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wpdiscuz

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-03-13); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
wpdiscuz

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-13: 1Mentions · 2026-06-09: 1Mentions · 2026-06-30: 1PoC Mentioned / Linked · 2026-06-30: 1Technical Details · 2026-03-13: 1Technical Details · 2026-06-30: 103-1306-0906-30
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-131
Disclosure1
2026-06-091
General1
2026-06-301
Disclosure1
Full discourse3 posts
  • kmkz@kmkz_security
    Disclosure

    I underplayed this one: so I fixed it ! Voltronic Power SNMP Web Pro : CVE-2026-22192 + CVE-2026-22199 / CVSS 10.0 > In a nutshell: Client-side auth bypass, pre-auth path traversal, /etc/shadow, offline crack, SSH root on an industrial UPS. Just another trusted crappy box in the rack becoming the perfect initial access inside the plant(s). 👉Details: https://tinyurl.com/upsremoteroot Kind of things (and way more!) we will talk about during #BSidesOT / ICS #Paris 2026 : Join us ! #OTSecurity #ICS #OffensiveSecurity

    Post summary

    The post discloses two new CVEs affecting Voltronic Power SNMP Web Pro, detailing authentication bypass and path traversal that allow SSH root access, and links to a page for further technical information.

    030801.1K
    19.8K followersView on X
  • kmkz@kmkz_security
    General

    @co11ateral I confirm: CVE-2026-22199 ;)

    Post summary

    The tweet merely confirms the existence of CVE-2026-22199 without providing any additional technical, exploit, or mitigation information.

    10021606
    19.7K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-22199 wpDiscuz before 7.6.47 contains a vote manipulation vulnerability that allows attackers to manipulate comment votes by obtaining fresh nonces and bypassing rate limit… https://www.cve.org/CVERecord?id=CVE-2026-22199

    Post summary

    The tweet announces a new vulnerability in wpDiscuz (CVE-2026-22199) and provides brief technical details, but does not mention a PoC, exploit code, active exploitation, or patch.

    00000110
    56.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgvectorswpdiscuz-wordpress-

Explore more