CVE-2026-96882
📛 CVE Title
TaleLin lin-cms-spring-boot book Endpoint BookController.java searchBook improper authorization
Description
A vulnerability was identified in TaleLin lin-cms-spring-boot up to 0.2.1. Affected by this vulnerability is the function searchBook of the file src/main/java/io/github/talelin/latticy/controller/v1/BookController.java of the component book Endpoint. The manipulation leads to improper authorization. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- VulDB
- CVSS severity
- MEDIUM
- CVSS score
- 6.9 / 10
- CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P- Effective score
- 6.9 / 10 MEDIUM source: CNA overview
- CWE(s)
-
CWE-285,CWE-266 - Reserved
- 2026-09-23
- Published
- 2026-09-24 02:30 UTC
- Last updated
- 2026-09-24 02:30 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/96xxx/CVE-2026-96882.json
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2026-09-24 03:16:58 UTC
- NVD last modified
- 2026-09-24 14:40:36 UTC
- NVD CVSS v3.1
- 5.3 / 10 MEDIUM source: cna@vuldb.com
- NVD CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N- Exploitability subscore
- 3.9 / 10
- Impact subscore
- 1.4 / 10
- EPSS score
- 0.0029 (probability of exploitation in next 30 days)
- EPSS percentile
- 18.77% vs all CVEs — higher = more likely to be exploited, as of 2026-09-24
NVD / KEV / EPSS data refreshed 2026-09-25 04:28 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-85779 - Assigner
- VulDB
- Published
- Sep 24, 2026, 2:30:09 AM
- Updated
- Sep 24, 2026, 2:30:09 AM
- EUVD base score (CVSS 4.0)
-
6.9 / 10
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P - EUVD-reported EPSS
- 0.2900
- Vendors
- TaleLin
- Products
-
lin-cms-spring-boot (0.2.0)lin-cms-spring-boot (0.2.1)
- Aliases
-
GHSA-fhj3-239p-54qc
ENISA description: A vulnerability was identified in TaleLin lin-cms-spring-boot up to 0.2.1. Affected by this vulnerability is the function searchBook of the file src/main/java/io/github/talelin/latticy/controller/v1/BookController.java of the component book Endpoint. The manipulation leads to improper authorization. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected products (1)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| TaleLin | lin-cms-spring-boot |
0.2.0 (affected),
0.2.1 (affected)
|
— |
Vendor references (5)
References embedded in the original CVE record by the assigning CNA.
- VDB-409080 | TaleLin lin-cms-spring-boot book Endpoint BookController.java searchBook improper authorization vdb-entrytechnical-description
- VDB-409080 | CTI Indicators (IOB, IOC, TTP, IOA) signaturepermissions-required
- CVE-2026-96882 | CVE Analysis and Report third-party-advisory
- Submit #906083 | https://github.com/logamee/lin-cms-spring-boot lin-cms 0.2.1 unauthorized access vulnerability third-party-advisory
- https://github.com/hhhh333/CVE/blob/main/Lin-CMS-%E6%9C%AA%E6%8E%88%E6%9D%833.md exploit
Web references (0)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
No web references attached yet.
NVD-tagged references (5)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- https://github.com/hhhh333/CVE/blob/main/Lin-CMS-%E6%9C%AA%E6%8E%88%E6%9D%833.md cna@vuldb.com
- https://vuldb.com/cve/CVE-2026-96882 cna@vuldb.com
- https://vuldb.com/submit/906083 cna@vuldb.com
- https://vuldb.com/vuln/409080 cna@vuldb.com
- https://vuldb.com/vuln/409080/cti cna@vuldb.com
Remediations (10)
-
web:app.opencve.io
Upgrade to Visual Studio 2022 version 17.14 or later and Visual Studio 2026 version 18.8 or later to include the fix Apply the Microsoft security update that addresses CVE - 2026 -62886 and verify that the vulnerable runtime components have been replaced Generated by OpenCVE AI on August 12, 2026 at 14:04 UTC.
2026-09-25 10:43 UTC -
web:blog.qualys.com
Executive Summary CVE - 2026 -68820 is an actively exploited Windows vulnerability listed in CISA's Known Exploited Vulnerabilities (KEV) Catalog, with a remediation deadline as suggested by CISA BOD 26-04. CISA BOD 26-04 introduces risk-based remediation timelines ranging from 3 to 14 days, increasing the pressure on teams to move quickly from patch availability to verified remediation ...
2026-09-25 10:43 UTC -
web:blog.talosintelligence.com
Microsoft has released its monthly security update for August 2026 , which includes 421 vulnerabilities affecting a range of products, including 62 that Microsoft marked as "critical."
2026-09-25 10:43 UTC -
web:connect.tenable.com
On August 11, Microsoft released its August 2026 Patch Tuesday release which patched 398 CVEs with 42 rated critical, 355 rated as important and one rated as moderate. This update includes patches for three zero-days, including one that was exploited in the wild. CVE - 2026 -68820 is an EoP vulnerability affecting Windows Ancillary Function Driver for WinSock. It received a CVSSv3 score of 7.0 ...
2026-09-25 10:43 UTC -
web:securityarsenal.com
Microsoft's August 2026 Patch Tuesday fixes 398 flaws — including CVE - 2026 -68820, a Windows kernel socket driver bug already exploited in the wild for SYSTEM escalation. Patch now.
2026-09-25 10:43 UTC -
web:support.microsoft.com
The September 8, 2026 update for Windows 10, version 1809 and Windows Server 2019 includes security and cumulative reliability improvements in .NET Framework 3.5 and 4.8. We recommend that you apply this update as part of your regular maintenance routines. Before you install this update, see the Prerequisites and Restart requirement sections. Summary Security Improvements CVE - 2026 -62886 - .NET ...
2026-09-25 10:43 UTC -
web:windowsforum.com
Microsoft has released fixes for CVE - 2026 -62886, .NET Elevation of Privilege Vulnerability, an Important-rated flaw in .NET that can allow an unauthorized attacker to elevate privileges locally through integer overflow or wraparound.
2026-09-25 10:43 UTC -
web:www.helpnetsecurity.com
Microsoft's August 2026 Patch Tuesday delivered 400+ security fixes, including one for an actively exploited zero-day flaw ( CVE - 2026 -68820).
2026-09-25 10:43 UTC -
web:www.sentinelone.com
CVE - 2026 -68820 is a privilege escalation vulnerability in Windows 10 1607. Learn about its impact, affected versions, and mitigation methods.
2026-09-25 10:43 UTC -
web:www.tenable.com
Microsoft patched 398 CVEs in August including three zero-day flaws, one exploited in the wild: CVE - 2026 -68820 in the Windows Ancillary Function Driver for WinSock.
2026-09-25 10:43 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2026-96882.json.
{
"containers": {
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:talelin:lin-cms-spring-boot:*:*:*:*:*:*:*:*"
],
"modules": [
"book Endpoint"
],
"product": "lin-cms-spring-boot",
"vendor": "TaleLin",
"versions": [
{
"status": "affected",
"version": "0.2.0"
},
{
"status": "affected",
"version": "0.2.1"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "hhhha (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was identified in TaleLin lin-cms-spring-boot up to 0.2.1. Affected by this vulnerability is the function searchBook of the file src/main/java/io/github/talelin/latticy/controller/v1/BookController.java of the component book Endpoint. The manipulation leads to improper authorization. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 5,
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:UR",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-285",
"description": "Improper Authorization",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-266",
"description": "Incorrect Privilege Assignment",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-24T02:30:09.259Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-409080 | TaleLin lin-cms-spring-boot book Endpoint BookController.java searchBook improper authorization",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/409080"
},
{
"name": "VDB-409080 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/409080/cti"
},
{
"name": "CVE-2026-96882 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-96882"
},
{
"name": "Submit #906083 | https://github.com/logamee/lin-cms-spring-boot lin-cms 0.2.1 unauthorized access vulnerability",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/906083"
},
{
"tags": [
"exploit"
],
"url": "https://github.com/hhhh333/CVE/blob/main/Lin-CMS-%E6%9C%AA%E6%8E%88%E6%9D%833.md"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-23T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-23T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-23T20:20:24.000Z",
"value": "VulDB entry last update"
}
],
"title": "TaleLin lin-cms-spring-boot book Endpoint BookController.java searchBook improper authorization",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-96882",
"datePublished": "2026-09-24T02:30:09.259Z",
"dateReserved": "2026-09-23T18:15:13.076Z",
"dateUpdated": "2026-09-24T02:30:09.259Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}