CVE-2026-19359 PUBLISHED

nxp-auto-goldvip gvip Lambda Function SitewiseCustomFunction access control

Assigner: VulDB
Reserved: 08.08.2026 Published: 09.08.2026 Updated: 09.08.2026

A security vulnerability has been detected in nxp-auto-goldvip gvip up to 1.4.0. Affected by this issue is the function SitewiseCustomFunction of the component Lambda Function Handler. Such manipulation leads to improper access controls. The attack can be launched remotely. Upgrading to version 1.15.0 can resolve this issue. Upgrading the affected component is advised. The project explains: "The reported IAM permission configuration is a known historical issue that was already addressed in 2024, beginning with GoldVIP version 1.13.0. The permissions were updated in subsequent releases, including version 1.15.0. In addition, we also sent a request to either update or deprecate the older release in the AWS SAR application repository."

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X
CVSS Score: 5.1

Product Status

Vendor nxp-auto-goldvip
Product gvip
Versions
  • Version 1.0 is affected
  • Version 1.1 is affected
  • Version 1.2 is affected
  • Version 1.3 is affected
  • Version 1.4.0 is affected
  • Version 1.15.0 is unaffected

Credits

  • changli (VulDB User) reporter
  • VulDB CNA Team coordinator

References

Problem Types

  • Improper Access Controls CWE
  • Incorrect Privilege Assignment CWE