CVE-2026-5842Disclosure

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A security vulnerability has been detected in decolua 9router up to 0.3.47. The impacted element is an unknown function of the file /api of the component Administrative API Endpoint. The manipulation leads to authorization bypass. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 0.3.75 is sufficient to resolve this issue. It is suggested to upgrade the affected component.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-285CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 1 mentions (2026-04-09); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-09: 1Mentions · 2026-04-10: 1Mentions · 2026-09-23: 1Technical Details · 2026-04-09: 1Technical Details · 2026-09-23: 104-0904-1009-23
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • DailyCVE@dailycve
    Disclosure

    🔴 Dashboard Settings API, Mass Assignment, #CVE-2026-5842 (Critical) -DC-Sep2026-2542 https://dailycve.com/dashboard-settings-api-mass-assignment-cve-2026-5842-critical-dc-sep2026-2542/

    Post summary

    Announces CVE-2026-5842 as a critical mass assignment vulnerability in a Dashboard Settings API; no exploit, PoC, patch, or active exploitation evidence is mentioned.

    0000039
    238 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-5842 📊 Severity: 7.3 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-5842 #CVE-2026-5842 #CVE #High #CyberSecurity #InfoSec https://t.co/lLaHW9a5M6

    Post summary

    A new vulnerability (CVE-2026-5842) with severity 7.3 and high risk level is announced, but no further technical details or mitigation information are provided.

    0000037
    123 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-5842 Authorization Bypass in Decolua 9router Up to 0.3.47 Administrative API Endpoint https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5842

    Post summary

    The entry announces an authorization bypass vulnerability in Decolua 9router’s administrative API (versions up to 0.3.47) without providing PoC, exploit code, or patch details.

    0000070
    4.0K followersView on X

Explore more