PT-2026-97803 · Blackcandy Org · Black Candy

·

CVE-2026-97061

·

Published

2026-09-24

·

Updated

2026-09-29

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Black Candy versions prior to 3.2.2
Description An issue exists where playlist search queries are not scoped to the authenticated session user. This allows any authenticated user to enumerate all playlists on the instance. Attackers can use blank or targeted search parameters via the 'SearchController' or 'Search::PlaylistsController' endpoints to retrieve playlist names belonging to other users without authorization.
Recommendations Update to a version newer than 3.2.1. Restrict access to the 'SearchController' and 'Search::PlaylistsController' endpoints to minimize the risk of unauthorized data retrieval.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-97061

Affected Products

Black Candy