Authorization bypass through user-controlled key in Misskey - CVE-2026-28433
Published: April 28, 2026
Misskey
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to authorization bypass through a user-controlled key in the import function when importing data by file ID. A remote user can supply the ID corresponding to another user's file to disclose sensitive information.
Exploitation requires knowledge of the ID corresponding to the target file.