Authorization bypass through user-controlled key in Misskey - CVE-2026-28431

 

Authorization bypass through user-controlled key in Misskey - CVE-2026-28431

Published: April 28, 2026


Vulnerability identifier: #VU128343
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-28431
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper access control in authorization checks when handling requests for protected data. A remote user can access limited portions of data that they would not normally be able to access to disclose sensitive information.

This issue occurs regardless of whether federation is enabled.


Affected software

Misskey

How to mitigate CVE-2026-28431

Install security update from vendor's website.

Misskey - update to 2026.3.1

External References

Related Security Bulletins