CVE-2026-4542Disclosure

LOWCVSS 2.1 · LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability has been found in SSCMS 4.7.0. The affected element is an unknown function of the file LayerImageController.Submit.cs of the component layerImage Endpoint. Such manipulation of the argument filePaths leads to path traversal. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-03-22); latest day: 2
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-03-22: 3Mentions · 2026-03-23: 2Technical Details · 2026-03-22: 303-2203-23
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-223
Disclosure3
2026-03-232
Disclosure1General1
Full discourse5 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-4542 A vulnerability has been found in SSCMS 4.7.0. The affected element is an unknown function of the file LayerImageController.Submit.cs of the component layerImage Endpoi… https://www.cve.org/CVERecord?id=CVE-2026-4542 ----- Traducción: CVE-2026-4542 Se … http://infoflow.cloud`

    Post summary

    An initial disclosure of CVE-2026-4542 affecting SSCMS 4.7.0, with no further technical detail or evidence of exploitation reported.

    0000015
    61 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-4542 A vulnerability has been found in SSCMS 4.7.0. The affected element is an unknown function of the file LayerImageController.Submit.cs of the component layerImage Endpoi… https://www.cve.org/CVERecord?id=CVE-2026-4542

    Post summary

    A brief mention of a vulnerability in SSCMS 4.7.0 is provided without any PoC, exploit, patch, or technical details, indicating a general informational note.

    00000136
    56.8K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-4542 📊 Severity: 5.4 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-4542 #CVE-2026-4542 #CVE #Medium  #CyberSecurity #InfoSec https://t.co/cBCAFWjIr8

    Post summary

    A tweet alerts the public to CVE-2026-4542, noting its medium severity and unspecified affected products, but provides no exploit or remediation details, making it primarily a disclosure.

    0000016
    111 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4542 Path Traversal in SSCMS 4.7.0 via LayerImageController.Submit Endpoint https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4542

    Post summary

    The entry reports a path traversal flaw in SSCMS 4.7.0 affecting the LayerImageController.Submit endpoint, outlining the technical details without mentioning patches or active exploitation.

    0000043
    4.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4542 - SSCMS layerImage Endpoint LayerImageController.Submit.cs path traversal Intel Report: https://ift.tt/82WbIDY

    Post summary

    A new path traversal vulnerability (CVE‑2026‑4542) in the SSCMS LayerImage endpoint has been reported via an Intel Report.

    0000019
    292 followersView on X

Explore more