GHSA-22vq-6hm4-vrwc · Severity: medium — When the DLP is active, the UserCheck Web Portal contains an input-handling issue in the...
When the DLP is active, the UserCheck Web Portal contains an input-handling issue in the UserChoice flow. Under specific conditions, an attacker who can access the UserCheck Ask page could attempt to manipulate the Security Gateway's stored DLP/UserCheck incident information. This could lead to disruptions such as loss of stored incident entries, incorrect handling of pending approvals, or resource impact if the issue is abused repeatedly. Exposure is reduced if the UserCheck Portal is not accessible from untrusted networks.
Conclusion & alert: CVE-2026-48134 is rated Moderate Risk (54.2/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 4.36%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-23 | 4.03% | 4.36% | +0.32% |
| 2 | 2026-06-15 | 0.06% | 4.03% | +3.98% |
| 3 | 2026-05-27 | — | 0.06% | — |
Full EPSS history (3 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.6 | 3.1 | MEDIUM |
|
2.2 | 3.4 | [email protected] |
GHSA-22vq-6hm4-vrwc · Severity: medium — When the DLP is active, the UserCheck Web Portal contains an input-handling issue in the...
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| No affected products in dataset. | |||