Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 05 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 05 Aug 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Misskey
Misskey misskey |
|
| Vendors & Products |
Misskey
Misskey misskey |
Mon, 03 Aug 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Misskey is an open source, federated social media platform. All Misskey servers running versions 2024.5.0 and later, but prior to 2026.5.4, contain a vulnerability in the Server Announcements API where insufficient permission checks allow attackers to access limited portions of data that they normally couldn't view. This vulnerability occurs whether or not federation is enabled. This issue has been fixed in version 2026.5.4. | |
| Title | Misskey: Improper Authorization in the Announcements API | |
| Weaknesses | CWE-285 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-05T14:24:48.433Z
Reserved: 2026-05-20T18:46:58.289Z
Link: CVE-2026-48115
Updated: 2026-08-05T14:24:45.708Z
Status : Received
Published: 2026-08-03T22:16:49.593
Modified: 2026-08-05T15:16:51.267
Link: CVE-2026-48115
No data.
OpenCVE Enrichment
Updated: 2026-08-05T09:45:06Z