Improper Privilege Management in wongcyrus ExcelLexBot Lambda Function
CVE-2026-19360

5.1MEDIUM

Key Information:

Vendor

Wongcyrus

Vendor
CVE Published:
9 August 2026

What is CVE-2026-19360?

A vulnerability has been identified in the wongcyrus ExcelLexBot, specifically impacting the Lambda Function Handler, ExcelLexBotS3TriggerFunction, in versions up to 0.0.3. This flaw allows for remote manipulation that can lead to improper privilege management. The issue arises primarily in products no longer maintained by the vendor. Despite attempts to communicate with the vendor regarding this disclosure, no response has been received.

Affected Version(s)

ExcelLexBot 0.0.1

ExcelLexBot 0.0.2

ExcelLexBot 0.0.3

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

changli (VulDB User)
VulDB CNA Team
.