PT-2026-34814 · Xibo · Xibo

·

CVE-2026-31956

·

Published

2026-04-24

·

Updated

2026-04-25

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Xibo versions prior to 4.4.1
Description An authenticated user can manually construct a URL to preview campaigns or regions and export saved reports belonging to other users. This is possible for authorized users with privileges to access pages for Layout Management, Campaign Management, or Saved Reports.
Recommendations Upgrade to version 4.4.1.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-31956
GHSA-Q6RV-8HHJ-3FR8

Affected Products

Xibo