CVE-2026-42291General

LOWCVSS 6.8 · MEDIUM

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

SysReptor is a fully customizable pentest reporting platform. From version 2026.4 to before version 2026.27, the endpoints for reading and creating sharing links for personal notes is not properly authorized. This allows authenticated attackers who obtain the note ID of victim users to list and create sharing links to those users' personal notes. This gives attackers read and write access to notes of other users. This exploit works in both SysReptor Professional and Community. In Community it has, however, no impact because all users have superuser permissions and can list personal notes of other users at /admin/pentests/usernotebookpage/. This issue has been patched in version 2026.27.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-05-09)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-06: 1Mentions · 2026-05-09: 2PoC Mentioned / Linked · 2026-05-06: 1Technical Details · 2026-05-06: 1Technical Details · 2026-05-09: 105-0605-09
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-061
Disclosure1
2026-05-092
General2
Full discourse3 posts
  • Robin Lunde@pwn_panda
    Disclosure

    Writeup from the CVE I found in SysReptor (and some parts around how I use AI currently): https://robinlunde.com/blog/cve-2026-42291-read-write-access-to-personal-notes-by-sharing-link-creation-with-no-authorization-in-sysreptor-professional/ Feedback welcome :)

    Post summary

    The author shares a blog post detailing the discovery of CVE‑2026‑42291 in SysReptor Professional, explaining how the flaw allows unauthorized read‑write access via a sharing link.

    0001036
    115 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-42291 SysReptor is a fully customizable pentest reporting platform. From version 2026.4 to before version 2026.27, the endpoints for reading and creating sharing links for … https://www.cve.org/CVERecord?id=CVE-2026-42291

    Post summary

    The text notes that CVE‑2026‑42291 affects certain sharing‑link endpoints in SysReptor, but provides no further technical specifics or actionable information.

    0000094
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-42291 Improper Authorization in SysReptor Personal Notes Sharing Links 2026.4-2026.26 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42291

    Post summary

    The post announces CVE-2026-42291 as an improper authorization flaw in SysReptor Personal Notes sharing links, but offers no proof‑of‑concept, exploit code, active exploitation evidence, or patch information.

    0000040
    4.0K followersView on X

Explore more