CVE-2026-6574General

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability has been found in osuuu LightPicture up to 1.2.2. This issue affects some unknown processing of the file /public/install/lp.sql of the component API Upload Endpoint. Such manipulation of the argument key leads to hard-coded credentials. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-259CWE-798

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • General: 3 classified signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-04-19); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-19: 3Mentions · 2026-04-20: 1Technical Details · 2026-04-19: 1Technical Details · 2026-04-20: 104-1904-20
Signal classification2 categories
General
375.0%
Disclosure
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-193
Disclosure1General2
2026-04-201
General1
Full discourse4 posts
  • CTIWatch@ctiwatchcloud
    General

    🔍 Today's Top Vulnerabilities 🟠 CVE-2026-6563 | CVSS 8.8 🟠 CVE-2026-6574 | CVSS 7.3 🟠 CVE-2026-6569 | CVSS 7.3 🔗 http://ctiwatch.cloud/vulnerabilities #CVE #Vulnerability #ThreatIntel

    Post summary

    The tweet lists a few CVEs with their CVSS scores and links to a site, but provides no deeper technical, exploit, or mitigation information.

    0000075
    5.6K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-6574 A vulnerability has been found in osuuu LightPicture up to 1.2.2. This issue affects some unknown processing of the file /public/install/lp.sql of the component API Upl… https://www.cve.org/CVERecord?id=CVE-2026-6574 ----- Traducción: CVE-2026-6574 Se … http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-6574 for osuuu LightPicture, providing minimal details without any PoC, exploit, patch, or evidence of active exploitation.

    0000032
    72 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-6574 A vulnerability has been found in osuuu LightPicture up to 1.2.2. This issue affects some unknown processing of the file /public/install/lp.sql of the component API Upl… https://www.cve.org/CVERecord?id=CVE-2026-6574

    Post summary

    The text briefly notes a CVE in osuuu LightPicture, identifying an affected component but providing no further technical details, PoC, or remediation guidance.

    00000187
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-6574 Hard-Coded Credentials in osuuu LightPicture API Upload Endpoint Up to 1.2.2 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6574

    Post summary

    The snippet announces CVE‑2026‑6574 as a hard‑coded credential flaw in osuuu LightPicture, providing only a basic disclosure without any PoC, exploit, patch, or evidence of active exploitation.

    0000047
    4.0K followersView on X

Explore more