CVE-2026-5000Disclosure

LOWCVSS 6.9 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was detected in PromtEngineer localGPT up to 4d41c7d1713b16b216d8e062e51a5dd88b20b054. Impacted is the function LocalGPTHandler of the file backend/server.py of the component API Endpoint. The manipulation of the argument BaseHTTPRequestHandler results in missing authentication. The attack can be executed remotely. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-03-29)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-28: 1Mentions · 2026-03-29: 2Technical Details · 2026-03-28: 1Technical Details · 2026-03-29: 103-2803-29
Signal classification1 categories
Disclosure
3100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-281
Disclosure1
2026-03-292
Disclosure2
Full discourse3 posts
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-5000 📊 Severity: 7.3 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-5000 #CVE-2026-5000 #CVE #High #CyberSecurity #InfoSec https://t.co/KtVVyGkzDb

    Post summary

    The tweet announces CVE‑2026‑5000 as a high‑severity vulnerability affecting multiple products and directs readers to the NVD entry, but provides no PoC, exploit, or patch information.

    0000033
    123 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5000 A vulnerability was detected in PromtEngineer localGPT up to 4d41c7d1713b16b216d8e062e51a5dd88b20b054. Impacted is the function LocalGPTHandler of the file backend/serv… https://www.cve.org/CVERecord?id=CVE-2026-5000

    Post summary

    A new CVE (CVE-2026-5000) has been identified in PromtEngineer localGPT’s LocalGPTHandler function, but no details about the vulnerability type, exploitation, or remediation are provided.

    0000076
    56.9K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-5000 - PromtEngineer localGPT API Endpoint http://server.py LocalGPTHandler missing authentication Intel Report: https://ift.tt/l61UzO2

    Post summary

    The alert announces CVE-2026-5000 as a missing authentication flaw in a localGPT API endpoint, providing technical details but no PoC, patch, or exploitation evidence.

    0000016
    283 followersView on X

Explore more