CVE-2026-5252Disclosure

LOWCVSS 2.0 · LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A security flaw has been discovered in z-9527 admin 1.0/2.0. Affected is an unknown function of the file /server/routes/message.js of the component Message Create Endpoint. Performing a manipulation results in cross site scripting. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-01: 2Technical Details · 2026-04-01: 104-01
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-5252 📊 Severity: 3.5 🚨 Risk Level: Low 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-5252 #CVE-2026-5252 #CVE #Low #CyberSecurity #InfoSec https://t.co/lhG6WdFMyZ

    Post summary

    The tweet merely announces the existence of CVE‑2026‑5252, indicating a low severity (3.5) and supplying a link to the NVD record, but offers no additional technical or exploit information.

    0000028
    123 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5252 A security flaw has been discovered in z-9527 admin 1.0/2.0. Affected is an unknown function of the file /server/routes/message.js of the component Message Create Endpo… https://www.cve.org/CVERecord?id=CVE-2026-5252

    Post summary

    A new vulnerability (CVE‑2026‑5252) has been identified in z‑9527 admin v1.0/2.0, affecting an unknown function in the Message Create endpoint, with a reference to the CVE record for more details.

    00000104
    56.9K followersView on X

Explore more