PT-2026-28578 · Linkace · Linkace
Amemoyoi
·
Published
2026-03-27
·
Updated
2026-03-28
·
CVE-2026-33954
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
LinkAce versions prior to 2.5.3
Description
LinkAce is a self-hosted archive for website links. Versions prior to 2.5.3 allow disclosure of a private note attached to a non-private link to another authenticated user through the web interface. The API correctly enforces note visibility, but the web link detail page does not apply equivalent filtering. An authenticated user permitted to view another user’s
internal or public link can read that user’s private notes attached to the link.Recommendations
Update to version 2.5.3 or later.
Exploit
Fix
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linkace