PT-2026-83967 · Xibo · Xibo

·

CVE-2026-52730

·

Published

2026-08-31

·

Updated

2026-08-31

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Xibo versions prior to 4.4.3
Description Missing authorization in the Module::settingsForm function allows an authorized user with access to the Module View feature to view super admin-restricted module settings and leak the full module entity. This issue does not allow the modification of settings.
Recommendations Upgrade to version 4.4.3. Revoke Module View privileges from untrusted users as a temporary mitigation.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-52730
GHSA-6H64-J36J-H2V2

Affected Products

Xibo