CVE-2026-4993General

LOWCVSS 1.9 · LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability has been found in wandb OpenUI up to 0.0.0.0/1.0. This impacts an unknown function of the file backend/openui/config.py. The manipulation of the argument LITELLM_MASTER_KEY leads to hard-coded credentials. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-259CWE-798

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-28: 3Technical Details · 2026-03-28: 103-28
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets4 URLs
Full discourse3 posts
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-4993 📊 Severity: 3.3 🚨 Risk Level: Low 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-4993 #CVE-2026-4993 #CVE #Low #CyberSecurity #InfoSec https://t.co/IYhK5Dn0vC

    Post summary

    The tweet announces CVE-2026-4993 as a low‑severity issue but provides no technical insights, exploit details, or remediation guidance.

    0000025
    123 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-4993 A vulnerability has been found in wandb OpenUI up to 0.0.0.0/1.0. This impacts an unknown function of the file backend/openui/config.py. The manipulation of the argumen… https://www.cve.org/CVERecord?id=CVE-2026-4993

    Post summary

    The snippet announces CVE-2026-4993 for wandb OpenUI with minimal technical detail and no evidence of exploitation or mitigations.

    0000081
    56.9K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4993 - wandb OpenUI http://config.py hard-coded credentials Intel Report: https://ift.tt/wpGNfb9

    Post summary

    An alert highlights CVE-2026-4993, revealing hard‑coded credentials in wandb OpenUI's config.py, with no evidence of activity, PoC, exploit, or remediation.

    0000023
    283 followersView on X

Explore more