Authorization bypass through user-controlled key in Misskey - CVE-2026-28433

 

Authorization bypass through user-controlled key in Misskey - CVE-2026-28433

Published: April 28, 2026


Vulnerability identifier: #VU128342
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-28433
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to authorization bypass through a user-controlled key in the import function when importing data by file ID. A remote user can supply the ID corresponding to another user's file to disclose sensitive information.

Exploitation requires knowledge of the ID corresponding to the target file.


Affected software

Misskey

How to mitigate CVE-2026-28433

Install security update from vendor's website.

Misskey - update to 2026.3.1

External References

Related Security Bulletins