CVE-2026-5251General

LOWCVSS 2.1 · LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was identified in z-9527 admin 1.0/2.0. This impacts an unknown function of the file /server/routes/user.js of the component User Update Endpoint. Such manipulation of the argument isAdmin with the input 1 leads to dynamically-determined object attributes. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-913CWE-915

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-01: 3Technical Details · 2026-04-01: 104-01
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-5251 📊 Severity: 6.3 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-5251 #CVE-2026-5251 #CVE #Medium #CyberSecurity #InfoSec https://t.co/ZBV0AO6uxc

    Post summary

    A new CVE (CVE-2026-5251) with medium severity (CVSS 6.3) was announced, affecting unspecified products, with no technical details, PoC, exploitation status, or patch information provided.

    0000025
    123 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-5251 A vulnerability was identified in z-9527 admin 1.0/2.0. This impacts an unknown function of the file /server/routes/user.js of the component User Update Endpoint. Such … https://www.cve.org/CVERecord?id=CVE-2026-5251

    Post summary

    The brief mention of CVE-2026-5251 only notes a vulnerability in the User Update Endpoint of z‑9527 admin, without any PoC, exploit details, patch info, or technical specifics.

    00000105
    56.9K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-5251 - z-9527 admin User Update Endpoint user.js dynamically-determined object attributes Intel Report: https://ift.tt/XzNVcvs

    Post summary

    The alert announces the existence of CVE-2026-5251, noting a dynamic object attribute issue in an admin user update endpoint, but provides no PoC, exploit code, patch, or exploitation evidence.

    0000035
    281 followersView on X

Explore more