PT-2026-69984 · Mastodon · Mastodon

CVE-2026-72915

·

Published

2026-08-10

·

Updated

2026-08-17

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Mastodon versions 4.6.0-beta.1 through 4.6.3 Mastodon version 4.7.0-beta.1
Description An incorrect access control validation in the show action within app/controllers/admin/collections controller.rb allows any logged-in local user to access personally identifying information of other local users. This occurs because the controller utilizes the general collection policy instead of the admin collection policy namespace. The exposed data includes the user's current email address and last-used IP address.
Recommendations Update to version 4.6.4. Update to a version newer than 4.7.0-beta.1.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-MASTODON-2026-72915
CVE-2026-72915
GHSA-HX34-2PFW-2QFJ

Affected Products

Mastodon