PT-2026-94042 · Git+1 · Shlink

·

CVE-2026-92760

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Shlink versions prior to 5.1.7
Description Failure to enforce API key role restrictions occurs when issuing Mercure subscription tokens, which allows restricted keys to subscribe to all topics. This enables attackers possessing author-only or domain-only keys to access the 'mercure-info' endpoint and retrieve visit data, including referrer, user agent, geolocation, and full short URL objects for URLs that are outside their authorization boundary.
Recommendations Update to version 5.1.7 or later.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92760

Affected Products

Shlink