CVE-2026-4190Disclosure

MEDIUMCVSS 5.5 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability was detected in JawherKl node-api-postgres up to 2.5. This impacts the function User.getAll of the file models/user.js. The manipulation of the argument sort results in sql injection. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-89

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-03-15); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-15: 1Mentions · 2026-03-16: 1Mentions · 2026-05-01: 1Active Exploitation · 2026-05-01: 1Patch / Workaround · 2026-05-01: 1Technical Details · 2026-03-15: 1Technical Details · 2026-03-16: 1Technical Details · 2026-05-01: 103-1503-1605-01
Signal classification2 categories
Disclosure
266.7%
Active Exploitation
133.3%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-151
Disclosure1
2026-03-161
Disclosure1
2026-05-011
Active Exploitation1
Full discourse3 posts
  • OSec@Osec__
    Active Exploitation

    CVE-2026-4190 is being exploited in the wild. cPanel/WHM auth bypass. No credentials needed to gain full admin access. Patch now — don't wait for a maintenance window. If your server was internet-facing before patching, treat it as potentially compromised. Rotate all admin + root credentials, audit SSH keys and config files, and restrict management access to known IPs or VPN.

    Post summary

    The post confirms CVE-2026-4190 is currently exploited in the wild with an auth bypass in cPanel/WHM, urging immediate patching and credential rotation.

    11011117
    167 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4190 A vulnerability was detected in JawherKl node-api-postgres up to 2.5. This impacts the function User.getAll of the file models/user.js. The manipulation of the argument… https://www.cve.org/CVERecord?id=CVE-2026-4190

    Post summary

    CVE‑2026‑4190 is a newly detected issue in JawherKl node‑api-postgres v2.5, affecting the User.getAll function via argument manipulation, with no known PoC, exploitation, or patch detailed.

    00000101
    56.7K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4190 - JawherKl node-api-postgres user.js User.getAll sql injection Intel Report: https://ift.tt/SAm67sz

    Post summary

    The message alerts on CVE-2026-4190, identifying a SQL injection flaw in the JawherKl node-api-postgres User.getAll method and points to an Intel report for additional information.

    0000036
    336 followersView on X

Explore more