PT-2026-28578 · Linkace · Linkace

Amemoyoi

·

Publicado

2026-03-27

·

Atualizado

2026-03-28

·

CVE-2026-33954

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions LinkAce versions prior to 2.5.3
Description LinkAce is a self-hosted archive for website links. Versions prior to 2.5.3 allow disclosure of a private note attached to a non-private link to another authenticated user through the web interface. The API correctly enforces note visibility, but the web link detail page does not apply equivalent filtering. An authenticated user permitted to view another user’s internal or public link can read that user’s private notes attached to the link.
Recommendations Update to version 2.5.3 or later.

Exploit

Correção

Improper Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-33954
GHSA-88H3-CQ25-VW8Q

Produtos afetados

Linkace