PT-2026-69984 · Mastodon · Mastodon
CVE-2026-72915
·
Published
2026-08-10
·
Updated
2026-08-17
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Mastodon versions 4.6.0-beta.1 through 4.6.3
Mastodon version 4.7.0-beta.1
Description
An incorrect access control validation in the
show action within app/controllers/admin/collections controller.rb allows any logged-in local user to access personally identifying information of other local users. This occurs because the controller utilizes the general collection policy instead of the admin collection policy namespace. The exposed data includes the user's current email address and last-used IP address.Recommendations
Update to version 4.6.4.
Update to a version newer than 4.7.0-beta.1.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mastodon