PT-2026-6689 · Unknown · Easydiscuss

Creative-Graphics.Ch

+1

·

Published

2026-02-06

·

Updated

2026-02-18

·

CVE-2026-21626

CVSS v4.0

9.2

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions EasyDiscuss (affected versions not specified)
Description Access control settings for forum post custom fields are not enforced when data is output in JSON format. This results in an Access Control List (ACL) bypass, potentially leading to information disclosure. The issue allows unauthorized access to custom field data through JSON endpoints, requiring no authentication. This makes exploitation straightforward.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2026-21626

Affected Products

Easydiscuss