PT-2026-28578 · Linkace · Linkace

Amemoyoi

·

Published

2026-03-27

·

Updated

2026-03-28

·

CVE-2026-33954

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions LinkAce versions prior to 2.5.3
Description LinkAce is a self-hosted archive for website links. Versions prior to 2.5.3 allow disclosure of a private note attached to a non-private link to another authenticated user through the web interface. The API correctly enforces note visibility, but the web link detail page does not apply equivalent filtering. An authenticated user permitted to view another user’s internal or public link can read that user’s private notes attached to the link.
Recommendations Update to version 2.5.3 or later.

Exploit

Fix

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-33954
GHSA-88H3-CQ25-VW8Q

Affected Products

Linkace