Improper access control in Mastodon - CVE-2026-22246

 

Improper access control in Mastodon - CVE-2026-22246

Published: April 23, 2026


Vulnerability identifier: #VU126989
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-22246
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper access control in the severed relationships download functionality when handling requests for a particular severance event. A remote user can request lists of lost followers and followed users for other users' severance events to disclose sensitive information.

The leaked information does not include the name of the account which has lost follows and followers.


Affected software

Mastodon

How to mitigate CVE-2026-22246

Install security update from vendor's website.

Mastodon - addressed in versions 4.3.17, 4.4.11, 4.5.4

External References

Related Security Bulletins