CVE-2026-92356

A vulnerability was determined in a2ui-project a2ui 0.9/0.9.1. This issue affects the function updateComponents of the file basic_functions.ts of the component Update Components. Executing a manipulation can lead to resource consumption. The attack can be launched remotely. The project was informed of the problem early through an issue report but has not responded yet.

  • Published Sep 16, 2026
  • CVSS 5.3 medium
  • 0.5% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-92356 at the National Vulnerability Database