Sceawere

Vulnerability Detail

CVE-2026-19359UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

nxp-auto-goldvip Improper Access Control

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.7
Creation Date
4h ago
Vendor
nxp-auto-goldvip
Product
gvip
Attack Type
Improper Access Controls
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A security vulnerability has been detected in nxp-auto-goldvip gvip up to 1.4.0. Affected by this issue is the function SitewiseCustomFunction of the component Lambda Function Handler. Such manipulation leads to improper access controls. The attack can be launched remotely. Upgrading to version 1.15.0 can resolve this issue. Upgrading the affected component is advised. The project explains: "The reported IAM permission configuration is a known historical issue that was already addressed in 2024, beginning with GoldVIP version 1.13.0. The permissions were updated in subsequent releases, including version 1.15.0. In addition, we also sent a request to either update or deprecate the older release in the AWS SAR application repository."

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.7",
  "pubDate": "2026-08-09T17:16:21.860Z",
  "pubdate": "2026-08-09T17:16:21.860Z",
  "executiveSummary": "A security vulnerability categorized as improper access control has been identified in nxp-auto-goldvip gvip up to version 1.4.0. The vulnerability resides within the Lambda Function Handler component, specifically impacting the SitewiseCustomFunction function. This flaw allows remote attackers to manipulate IAM permission configurations, potentially leading to unauthorized access and privilege escalation within the affected cloud infrastructure. The risk implication involves unauthorized execution and data access stemming from overly permissive Identity and Access Management (IAM) policies. Exploitation can be conducted remotely without requiring complex pre-existing conditions, leveraging the inherently misconfigured historical permission set present in the older AWS Serverless Application Repository (SAR) deployments. To mitigate this risk, users are strongly advised to upgrade to version 1.15.0 or later, which incorporates the necessary permission remediations addressed beginning with GoldVIP version 1.3.0.",
  "technicalDetails": "The vulnerability stems from an insecure Identity and Access Management (IAM) permission configuration within the Lambda Function Handler component of the nxp-auto-goldvip gvip project. Specifically, the function SitewiseCustomFunction is deployed with overly broad execution permissions that violate the principle of least privilege. This constitutes a design-level improper access control flaw inherent in the affected software versions up to 1.4.0.\nThe attack vector is remote, allowing malicious actors or unauthorized entities to interact with the exposed AWS Lambda function handlers and leverage the excessive IAM permissions assigned to the execution role. Because the permission boundaries are improperly scoped, an attacker capable of invoking or interacting with the vulnerable function can execute actions unintended by the system architecture, potentially leading to unauthorized resource access, data exposure, or lateral movement within the cloud environment.\nThe root cause is traceable to legacy IAM policy templates utilized during the packaging and deployment of the AWS SAR application repository artifacts. The execution flow relies on the SitewiseCustomFunction executing under an overly permissive role, which lacks granular resource restrictions. Consequently, any interaction that triggers the flawed function logic operates with privileges exceeding operational necessity.\nAffected versions include nxp-auto-goldvip gvip up to version 1.4.0. The vulnerability does not require local system access, relying instead on network exposure inherent to cloud-hosted serverless functions with misconfigured access controls. Authentication and privilege requirements depend on the specific exposure of the Lambda Function Handler, but the core issue permits exploitation by principals able to interface with the targeted function endpoints."
}
CVE-2026-19359: nxp-auto-goldvip Improper Access Control (MEDIUM Severity, CVSS: 4.7) - Sceawere