CVE-2026-3969Disclosure

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was detected in FeMiner wms up to 1.0. This impacts an unknown function of the file /wms-master/src/basic/depart/depart_add_bg.php of the component Basic Organizational Structure Module. Performing a manipulation of the argument Name results in sql injection. The attack may be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 3 mentions (2026-03-12); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-12: 3Mentions · 2026-03-13: 1Technical Details · 2026-03-12: 303-1203-13
Signal classification2 categories
Disclosure
250.0%
General
250.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-123
Disclosure2General1
2026-03-131
General1
Full discourse4 posts
  • EdgeDetectOps@EdgeDetectOps
    General

    Hours now matter the way days used to. The patch team at a mid-sized logistics company got the alert at 2:47 PM on a Tuesday. CVE-2026-3969 in their FeMiner warehouse management system. Priority level unknown. Impact scope unclear.

    Post summary

    A brief incident alert referencing CVE-2026-3969 in a FeMiner system, with no further technical or actionable details.

    1000037
    14 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-3969 📊 Severity: 7.3 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-3969 #CVE-2026-3969 #CVE #High  #CyberSecurity #InfoSec https://t.co/JgMABwUUa8

    Post summary

    The tweet announces the new CVE-2026-3969 with a severity score of 7.3, but provides no PoC, exploit, or patch information.

    0000036
    96 followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-3969 - FeMiner - wms - https://www.redpacketsecurity.com/cve-alert-cve-2026-3969-feminer-wms/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-3969 #feminer #wms

    Post summary

    The post announces a CVE alert for CVE-2026-3969 targeting FeMiner WMS and provides a link to an external page, but offers no PoC, exploit code, or patch details.

    0000078
    3.5K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-3969 A vulnerability was detected in FeMiner wms up to 1.0. This impacts an unknown function of the file /wms-master/src/basic/depart/depart_add_bg.php of the component Basi… https://www.cve.org/CVERecord?id=CVE-2026-3969

    Post summary

    The post announces CVE‑2026‑3969, noting an unknown function in a specific file of FeMiner wms, but does not provide details on exploitation, patching, or PoC availability.

    00000123
    56.7K followersView on X

Explore more