Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

CVE-2026-73992 -- CVSS 9.9 Vulnerability Briefing

CVE-2026-73992 | CVSS 9.9 (Critical) | Exploit: PoC available

What Is It

CVE-2026-73992 is a critical subscriber remote code execution vulnerability affecting Query Wrangler versions 1.5.57 and earlier.

Technical Detail

The vulnerability allows a subscriber-level attacker to execute code remotely through Query Wrangler. The available information indicates that successful exploitation can result in remote code execution in the context of the affected Query Wrangler deployment. Technical details on the vulnerable request path, required subscriber permissions, and affected deployment configurations have not yet been confirmed.

Exploitation Status

A proof of concept exploit is available. There is no indication in the provided data that exploitation has been confirmed in the wild, and CVE-2026-73992 is not listed in CISA's Known Exploited Vulnerabilities catalog.

Who Is Targeting This

No specific threat actor attribution at this time.

What To Do

Prioritize updating Query Wrangler to a version later than 1.5.57 as soon as a vendor-provided fix is available. Until patched, restrict subscriber access to trusted users, review and limit permissions available to subscriber accounts, and avoid exposing Query Wrangler interfaces to untrusted networks. Monitor application and host logs for unusual subscriber-originated requests, unexpected child processes, command execution, script interpreter activity, or outbound connections from systems hosting Query Wrangler. No vendor workaround or specific detection signature has been confirmed in the available information.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →