Junglewise Threat Intelligence

CVE-2026-15752: zhinianboke xianyu-auto-reply missing authorization in Backend User Endpoint

CVE-2026-15752 · Severity: high · CVSS 7.3 · Published 2026-07-14

Executive brief

A security vulnerability exists in xianyu-auto-reply, an automated customer service system for the Xianyu platform. The software's user management interface fails to properly check for authorization, allowing anyone on the network to modify user accounts. In practice, an attacker could use this to change account details or grant themselves administrative privileges, potentially leading to a full takeover of the system and its automated trading functions.

Technical details

A missing authorization vulnerability (CWE-862) exists in the Backend User Endpoint of zhinianboke xianyu-auto-reply up to commit dcb445ad. The specific vulnerable endpoint is `PATCH /api/v1/users/{user_id}`, which lacks authentication dependencies. An unauthenticated remote attacker can submit a `UserUpdate` payload to modify sensitive fields such as 'role', 'status', 'email', and 'phone' for any known user ID. This allows for unauthorized account modification and privilege escalation to the 'ADMIN' role. The issue has been addressed in patch 19fc3282a1bb78a05c34945c088525d20e081cbd.

Affected products

  • zhinianboke xianyu-auto-reply up to dcb445ad97816ad65299a7580ee0c8c8f929da84

Timeline

  • 2026-06-13: patched: Patch 19fc3282a1bb78a05c34945c088525d20e081cbd applied to repository.
  • 2026-07-14: advisory: NVD/VulDB advisory published.

References

Related threats