CVE-2026-0019
published 2026-06-17CVE-2026-0019: In SettingsLib, there is a possible way to disable system components due to a logic error in the code. This could lead to local escalation of privilege with no…
high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.08%
0.2th percentile
In SettingsLib, there is a possible way to disable system components due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
In SettingsLib, there is a possible way to disable system components due to a logic error in the code.
ghsa_unreviewed·2026-06-17
CVE-2026-0019 [HIGH] CWE-269 In SettingsLib, there is a possible way to disable system components due to a logic error in the code.
In SettingsLib, there is a possible way to disable system components due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEList
CVE-2026-0019: In SettingsLib, there is a possible way to disable system components due to a logic error in the code
cvelistv5·2026-06-17·CVSS 7.8
CVE-2026-0019 [HIGH] CVE-2026-0019: In SettingsLib, there is a possible way to disable system components due to a logic error in the code
In SettingsLib, there is a possible way to disable system components due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
No detection rules found.
No public exploits indexed.
Wiz
RUSTSEC-2026-0019 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
[HIGH] RUSTSEC-2026-0019 Impact, Exploitability, and Mitigation Steps | Wiz
## RUSTSEC-2026-0019 :
Rust vulnerability analysis and mitigation
polymarket-client-sdk
Source : NVD
Published February 24, 2026
CNA Score N/A
Affected Technologies
Rust
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) N/A
Exploitation Probability (EPSS) N/A
Affected packages and libraries
tracing-check
Sources
NVD
Rust No Fix Added at: Feb 24, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related Rust vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA KEV exploit
Has fix
Published date
GHSA-2c6h-4899-wjxr
HIGH
8.7
Rust
scaly
No
No
Apr 04, 2026
Bugzilla
CVE-2026-58338 moodle: CSRF risk in user profile page reset [fedora-all]
bugzilla·2026-07-28
CVE-2026-58338 [MEDIUM] CVE-2026-58338 moodle: CSRF risk in user profile page reset [fedora-all]
CVE-2026-58338 moodle: CSRF risk in user profile page reset [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
MSA-26-0019: CSRF risk in user profile page reset
Description: The user profile page reset action did not include the
necessary token to prevent a CSRF risk.
Issue summary: CSRF risk in user profile page reset
Severity/Risk: Minor
Versions affected: 5.2, 5.1 to 5.1.4, 5.0 to 5.0.7, 4.5 to 4.5.11 and earlier
unsupported versions
Versions fixed: 5.2.1, 5.1.5, 5.0.8 and 4.5.12
Reported by: Paul Holden
Issue no.: MDL-88545
Bugzilla
CVE-2026-58338 moodle: CSRF risk in user profile page reset
bugzilla·2026-06-30
CVE-2026-58338 [MEDIUM] CVE-2026-58338 moodle: CSRF risk in user profile page reset
CVE-2026-58338 moodle: CSRF risk in user profile page reset
MSA-26-0019: CSRF risk in user profile page reset
Description: The user profile page reset action did not include the
necessary token to prevent a CSRF risk.
Issue summary: CSRF risk in user profile page reset
Severity/Risk: Minor
Versions affected: 5.2, 5.1 to 5.1.4, 5.0 to 5.0.7, 4.5 to 4.5.11 and earlier
unsupported versions
Versions fixed: 5.2.1, 5.1.5, 5.0.8 and 4.5.12
Reported by: Paul Holden
Issue no.: MDL-88545
2026-06-17
Published