PT-2026-56237 · Chevereto · Chevereto

·

CVE-2026-55417

·

Published

2026-07-07

·

Updated

2026-09-01

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Chevereto versions 3.7.5 through 4.5.3
Description An issue exists in the self-hosted media-sharing platform where the /json AJAX listing endpoint fails to enforce private profile restrictions. While the profile HTML route (/username) correctly returns a 404 error for private profiles, the /json endpoint allows an unauthenticated caller with a target user ID to retrieve all publicly-scoped images, which subsequently reveals the private username.
Recommendations Update to version 4.5.4.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55417
GHSA-H4JP-MXFX-G8XP

Affected Products

Chevereto