PT-2026-6689 · Unknown · Easydiscuss
Creative-Graphics.Ch
+1
·
Published
2026-02-06
·
Updated
2026-02-18
·
CVE-2026-21626
CVSS v4.0
9.2
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
EasyDiscuss (affected versions not specified)
Description
Access control settings for forum post custom fields are not enforced when data is output in JSON format. This results in an Access Control List (ACL) bypass, potentially leading to information disclosure. The issue allows unauthorized access to custom field data through JSON endpoints, requiring no authentication. This makes exploitation straightforward.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Easydiscuss