CVE-2026-32662 identifies the presence of development and test API endpoints that mirror production functionality, potentially leading to information exposure. This vulnerability is rated Medium severity with a CVSS score of 5.3, allowing network-based exploitation with low complexity and no required privileges or user interaction, resulting in a low confidentiality impact. There is currently no evidence of active exploitation, nor is exploit code publicly available in common databases. Community discussion and media coverage are absent, and its extremely low EPSS score indicates a very low probability of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.12.2026CPE matchmatch criteria | cpe:2.3:a:mygardyn:cloud_api:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.