Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Shohruh Yoldoshov

#41834of 56,330
6.9Total CVSS
Vulnerabilities · 1
PT-2026-88915
6.9
2026-09-09
Alchemycms · Alchemycms · CVE-2026-86777
AlchemyCMS versions before 7.4.16 and 8.x before 8.3.6 fail to authorize access to the GET /api/nodes endpoint, allowing unauthenticated attackers to retrieve all navigation nodes. Attackers can access the endpoint without authentication to disclose restricted page names, URL paths, and internal URLs from all sites and languages.