PT-2026-95022 · Scoold · Scoold

·

CVE-2026-54676

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Scoold versions prior to 1.69.0
Description Users with personal API tokens can retrieve replies from questions in private spaces they are not authorized to access. This occurs because the getPostReplies() function in ApiController.java fails to apply the canAccessSpace check before returning data from the 'GET /api/posts/{id}/answers' endpoint. The issue is exploitable when scoold.api user access enabled and scoold.api enabled are set to true and a token holder identifies or enumerates a private question identifier. Consequently, while the question endpoint may deny access, the answers endpoint returns private reply bodies, exposing confidential team or project discussions.
Recommendations Update to version 1.69.0. As a temporary mitigation, set scoold.api user access enabled or scoold.api enabled to false to disable API access.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54676
GHSA-2CFF-PPF7-PC42

Affected Products

Scoold