πŸ” CVE Alert

CVE-2026-19932

MEDIUM 6.3

DefaultFuction Notice-System-Managent NoticeController execute GroovyShell.evaluate code injection

CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
0th

A security flaw has been discovered in DefaultFuction Notice-System-Managent 2.0. This issue affects the function GroovyShell.evaluate of the file /execute of the component NoticeController. The manipulation results in code injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. The project confirms, that "it’s being processed".

CWE CWE-94 CWE-74
Vendor defaultfuction
Product notice-system-managent
Published Aug 16, 2026
Stay Ahead of the Next One

Get instant alerts for defaultfuction notice-system-managent

Be the first to know when new medium vulnerabilities affecting defaultfuction notice-system-managent are published β€” delivered to Slack, Telegram or Discord.

Get Free Alerts β†’ Free Β· No credit card Β· 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

DefaultFuction / Notice-System-Managent
2.0

References

NVD β†— CVE.org β†— EPSS Data β†—
vuldb.com: https://vuldb.com/vuln/390703 vuldb.com: https://vuldb.com/vuln/390703/cti vuldb.com: https://vuldb.com/cve/CVE-2026-19932 vuldb.com: https://vuldb.com/submit/872648 github.com: https://github.com/DefaultFuction/Notice-System-Managent/issues/1 github.com: https://github.com/DefaultFuction/Notice-System-Managent/

Credits

πŸ” Practice (VulDB User) VulDB CNA Team