Information disclosure in Opencast - CVE-2025-61906
Published: April 23, 2026
Opencast
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper workflow handling in the editor when processing save and publish actions. A remote user can trigger unintended publication of media to disclose sensitive information.
Exploitation requires write access to an event and user interaction in the editor, specifically clicking "Save & Publish" before selecting the "Save" option.