HIGHVulnerability

CVE-2026-82815

A flaw has been found in MegaEase EaseProbe up to 2.3.0. Affected is the function realIP of the file web/server.go of the component Middleware. This manipulation of the argument X-Forwarded-For/X-Real-IP/True-Client-IP causes improper access controls. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Properties

severity
HIGH
score
7.3
epss_score
0.00375
cve_id
CVE-2026-82815
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
published_at
2026-08-31T18:17:24.280
last_modified
2026-09-01T20:48:22.513
epss_percentile
0.30651

Related Entities (4)

ENRICHED_BY (1)

[Source]FIRST EPSS

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (2)

[Weakness]Incorrect Privilege Assignment
[Weakness]Improper Access Control

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-82815 — Ninja Signal Threat Intelligence | Ninja Signal