PT-2026-67527 · Misskey · Misskey

CVE-2026-48115

·

Published

2026-08-03

·

Updated

2026-08-03

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Misskey versions 2024.5.0 through 2026.5.3
Description Insufficient permission checks in the Server Announcements API allow attackers to access limited portions of data that are normally restricted. This issue persists regardless of whether federation is enabled.
Recommendations Update to version 2026.5.4.

Exploit

Fix

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48115
GHSA-J49Q-76HX-MV8F

Affected Products

Misskey