PatchSiren cyber security CVE debrief
CVE-2026-39639 redpixelstudios CVE debrief
A Missing Authorization vulnerability was found in the redpixelstudios RPS Include Content plugin. This issue allows for Exploiting Incorrectly Configured Access Control Security Levels and affects the plugin from n/a through version 1.2.2. The vulnerability has a CVSS score of 6.5 and is classified as MEDIUM severity. Users should review and adjust access control configurations for the plugin to ensure proper authorization levels.
- Vendor
- redpixelstudios
- Product
- RPS Include Content
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-08
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-08
- Advisory updated
- 2026-07-24
Who should care
Users of the RPS Include Content plugin, especially those with versions from n/a to 1.2.2, should be aware of this vulnerability and take necessary actions to secure their installations. This includes reviewing access control configurations and monitoring plugin updates.
Technical summary
The CVE-2026-39639 vulnerability has a CVSS score of 6.5 and is classified as MEDIUM severity. It was published on 2026-04-08T09:16:34.670Z and last modified on 2026-07-24T21:10:00.143Z. The vulnerability is related to CWE-862, which involves Missing Authorization. The vulnerability affects RPS Include Content plugin versions from n/a through 1.2.2.
Defensive priority
Medium priority should be given to updating the RPS Include Content plugin to a version beyond 1.2.2 to mitigate this vulnerability. Additionally, review and adjust access control configurations for the plugin to ensure proper authorization levels.
Recommended defensive actions
- Update the RPS Include Content plugin to the latest version available beyond 1.2.2.
- Review and adjust access control configurations for the plugin to ensure proper authorization levels.
- Monitor plugin updates and security advisories for further information.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
Evidence notes
The CVE record was published on 2026-04-08T09:16:34.670Z and was last modified on 2026-07-24T21:10:00.143Z. The NVD entry is currently Deferred. The vulnerability affects RPS Include Content plugin versions from n/a through 1.2.2. Evidence is based on CVE.org and NVD detail page information.
Official resources
-
CVE-2026-39639 CVE record
CVE.org
-
CVE-2026-39639 NVD detail
NVD
-
Source item URL
nvd_modified
- Mitigation or vendor reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-08T09:16:34.670Z and has not been modified since then. The NVD entry is currently Deferred.