PT-2026-6689 · Unknown · Easydiscuss

Creative-Graphics.Ch

+1

·

Publicado

2026-02-06

·

Atualizado

2026-02-18

·

CVE-2026-21626

CVSS v4.0

9.2

Crítica

VetorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions EasyDiscuss (affected versions not specified)
Description Access control settings for forum post custom fields are not enforced when data is output in JSON format. This results in an Access Control List (ACL) bypass, potentially leading to information disclosure. The issue allows unauthorized access to custom field data through JSON endpoints, requiring no authentication. This makes exploitation straightforward.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-21626

Produtos afetados

Easydiscuss