CVE-2026-19360: wongcyrus ExcelLexBot Lambda Function ExcelLexBotS3TriggerFunction privileges management
A vulnerability was detected in wongcyrus ExcelLexBot up to 0.0.3. This affects the function ExcelLexBotS3TriggerFunction of the component Lambda Function Handler. Performing a manipulation results in improper privilege management. The attack may be initiated remotely. The vendor was contacted early about this disclosure but did not respond in any way. This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19360?
CVE-2026-19360 has a medium severity rating of 4.7.
How do I fix CVE-2026-19360?
To mitigate CVE-2026-19360, ensure proper privilege management configurations are applied to the ExcelLexBotS3TriggerFunction.
What component is affected by CVE-2026-19360?
CVE-2026-19360 affects the Lambda Function Handler of the ExcelLexBot component.
Can CVE-2026-19360 be exploited remotely?
Yes, CVE-2026-19360 can be exploited remotely due to improper privilege management.
What is the impact of CVE-2026-19360?
The impact of CVE-2026-19360 includes potential unauthorized access and manipulation of privileges within the vulnerable function.