CVE-2026-73992 -- CVSS 9.9 Vulnerability Briefing
CVE-2026-73992 | CVSS 9.9 (Critical) | Exploit: PoC available
What Is It
CVE-2026-73992 is a critical subscriber remote code execution vulnerability affecting Query Wrangler versions 1.5.57 and earlier.
Technical Detail
The vulnerability allows a subscriber-level attacker to execute code remotely through Query Wrangler. The available information indicates that successful exploitation can result in remote code execution in the context of the affected Query Wrangler deployment. Technical details on the vulnerable request path, required subscriber permissions, and affected deployment configurations have not yet been confirmed.
Exploitation Status
A proof of concept exploit is available. There is no indication in the provided data that exploitation has been confirmed in the wild, and CVE-2026-73992 is not listed in CISA's Known Exploited Vulnerabilities catalog.
Who Is Targeting This
No specific threat actor attribution at this time.
What To Do
Prioritize updating Query Wrangler to a version later than 1.5.57 as soon as a vendor-provided fix is available. Until patched, restrict subscriber access to trusted users, review and limit permissions available to subscriber accounts, and avoid exposing Query Wrangler interfaces to untrusted networks. Monitor application and host logs for unusual subscriber-originated requests, unexpected child processes, command execution, script interpreter activity, or outbound connections from systems hosting Query Wrangler. No vendor workaround or specific detection signature has been confirmed in the available information.