CVE-2026-4992Disclosure

LOWCVSS 2.1 · LOW

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw has been found in wandb OpenUI up to 1.0. This affects the function create_share/get_share of the file backend/openui/server.py of the component HTMLAnnotator Component. Executing a manipulation of the argument ID can lead to HTML injection. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • 4 total mentions across 1 day

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-03-28: 4Technical Details · 2026-03-28: 303-28
Signal classification1 categories
Disclosure
4100.0%
Referenced assets5 URLs
Full discourse4 posts
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4992 - wandb OpenUI HTMLAnnotator http://server.py get_share HTML injection Intel Report: https://ift.tt/t24YzX3

    Post summary

    The tweet announces CVE-2026-4992 as an HTML injection flaw in wandb OpenUI, offering an Intel report link but lacking PoC, exploit, patch, or exploitation details.

    0000041
    283 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4992 - wandb OpenUI HTMLAnnotator http://server.py get_share HTML injection Intel Report: https://ift.tt/6z0pRue

    Post summary

    The post announces CVE-2026-4992 as an HTML injection flaw in the wandb OpenUI HTMLAnnotator’s get_share endpoint, providing a link to an intel report, but it offers no evidence of exploitation, PoC, or patch.

    0000050
    283 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4992 - wandb OpenUI HTMLAnnotator http://server.py get_share HTML injection Intel Report: https://ift.tt/B3Dnjf1

    Post summary

    The text announces CVE‑2026‑4992 as an HTML injection issue in wandb OpenUI's HTMLAnnotator, providing minimal technical detail but no PoC, exploit, patch, or evidence of active exploitation.

    0000048
    283 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4992 A flaw has been found in wandb OpenUI up to 1.0. This affects the function create_share/get_share of the file backend/openui/server.py of the component HTMLAnnotator Co… https://www.cve.org/CVERecord?id=CVE-2026-4992

    Post summary

    The message announces a flaw in Wandb OpenUI's create_share/get_share functions, but provides only very limited detail and no evidence of exploitation or remediation.

    0000071
    56.9K followersView on X

Explore more