What is CVE-2026-19932?
A remote code injection vulnerability has been discovered in DefaultFuction Notice-System-Managent 2.0, specifically within the GroovyShell.evaluate function in the /execute file of the NoticeController component. This flaw allows a remote attacker to execute arbitrary code on the affected system. Since an exploit has been publicly released, affected systems should be patched or temporarily taken offline immediately.
Azərbaycanca: DefaultFuction Notice-System-Managent 2.0 versiyasının NoticeController komponentində yerləşən /execute faylındakı GroovyShell.evaluate funksiyası vasitəsilə uzaqdan kod inyeksiyası (code injection) zəifliyi aşkar edilib. Bu qüsur uzaqdan hücum edənə sistemdə ixtiyari kod icrasına imkan verir. Zəiflik üçün istismar kodu artıq ictimaiyyətə açıq olduğundan, təsirlənən sistemlərin dərhal yenilənməsi və ya müvəqqəti olaraq istifadədən çıxarılması tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
Which version of DefaultFuction Notice-System-Managent is affected by CVE-2026-19932?
This vulnerability affects version 2.0 of DefaultFuction Notice-System-Managent.
Which function in the affected component is exploited for CVE-2026-19932?
The vulnerability is exploited through the GroovyShell.evaluate function in the /execute file within the NoticeController component.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.