PT-2026-60804 · Fossasia+1 · Open-Event-Server

·

CVE-2026-63101

·

Published

2026-07-17

·

Updated

2026-07-17

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Open Event Server versions prior to 1.19.2
Description A missing authentication flaw allows unauthenticated attackers to export the complete member roster of any group, including names, email addresses, roles, and join dates. This is possible because the group followers CSV export endpoint lacks an authentication decorator. An attacker can use brute-force to enumerate sequential group IDs, trigger an export via an unauthenticated POST endpoint, and poll an unauthenticated task status endpoint to obtain a download URL for the member CSV.
Recommendations Update to version 1.19.2 or later.

Exploit

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63101

Affected Products

Open-Event-Server