A security vulnerability has been detected in nxp-auto-goldvip gvip up to 1.4.0. (CVE-2026-19359)
CVE-2026-19359 is a medium severity security vulnerability in the nxp-auto-goldvip gvip software up to version 1.4.0. The issue affects the SitewiseCustomFunction within the Lambda Function Handler component, leading to improper access controls. This vulnerability can be exploited remotely. The problem stems from a known historical IAM permission misconfiguration that was addressed starting with version 1.13.0, with further permission updates in version 1.15.0. Users are advised to upgrade to version 1.15.0 or later to remediate the issue.
AI Analysis
Technical Summary
This vulnerability (CVE-2026-19359) involves improper access control in the SitewiseCustomFunction of the Lambda Function Handler component in nxp-auto-goldvip gvip versions up to 1.4.0. The root cause is a misconfiguration of IAM permissions, which allows remote attackers to bypass intended access restrictions. The issue was identified as a historical problem and has been fixed starting with GoldVIP version 1.13.0, with additional permission corrections in version 1.15.0. The vendor has also requested updates or deprecation of older releases in the AWS SAR application repository to prevent continued use of vulnerable versions.
Potential Impact
The vulnerability allows remote attackers to bypass access controls due to improper IAM permission configuration, potentially leading to unauthorized access or actions within the affected component. The CVSS score of 4.7 (medium severity) reflects limited confidentiality, integrity, and availability impacts requiring high privileges but no user interaction. There are no known exploits in the wild at this time.
Mitigation Recommendations
A fix is available. Users should upgrade to version 1.15.0 or later of nxp-auto-goldvip gvip to resolve this vulnerability. The issue was addressed starting with version 1.13.0, with further permission updates in subsequent releases. Additionally, the vendor has requested updates or deprecation of older versions in the AWS SAR repository. No other mitigation actions are indicated by the vendor.
A security vulnerability has been detected in nxp-auto-goldvip gvip up to 1.4.0. (CVE-2026-19359)
Description
CVE-2026-19359 is a medium severity security vulnerability in the nxp-auto-goldvip gvip software up to version 1.4.0. The issue affects the SitewiseCustomFunction within the Lambda Function Handler component, leading to improper access controls. This vulnerability can be exploited remotely. The problem stems from a known historical IAM permission misconfiguration that was addressed starting with version 1.13.0, with further permission updates in version 1.15.0. Users are advised to upgrade to version 1.15.0 or later to remediate the issue.
CVSS v3.1
Score 4.7medium
Affected software
pkg:github/nxp-auto-goldvip/gvipRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CVE-2026-19359) involves improper access control in the SitewiseCustomFunction of the Lambda Function Handler component in nxp-auto-goldvip gvip versions up to 1.4.0. The root cause is a misconfiguration of IAM permissions, which allows remote attackers to bypass intended access restrictions. The issue was identified as a historical problem and has been fixed starting with GoldVIP version 1.13.0, with additional permission corrections in version 1.15.0. The vendor has also requested updates or deprecation of older releases in the AWS SAR application repository to prevent continued use of vulnerable versions.
Potential Impact
The vulnerability allows remote attackers to bypass access controls due to improper IAM permission configuration, potentially leading to unauthorized access or actions within the affected component. The CVSS score of 4.7 (medium severity) reflects limited confidentiality, integrity, and availability impacts requiring high privileges but no user interaction. There are no known exploits in the wild at this time.
Mitigation Recommendations
A fix is available. Users should upgrade to version 1.15.0 or later of nxp-auto-goldvip gvip to resolve this vulnerability. The issue was addressed starting with version 1.13.0, with further permission updates in subsequent releases. Additionally, the vendor has requested updates or deprecation of older versions in the AWS SAR repository. No other mitigation actions are indicated by the vendor.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-p9pf-mc7w-9q4h
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-19359"]
- Ecosystems
- []
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6a79f0f7bf8831d539f64b1b
Added to database: 08/10/2026, 15:40:39 UTC
Last enriched: 08/10/2026, 16:13:39 UTC
Last updated: 08/10/2026, 17:40:59 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.