Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 17 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 16 Sep 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Shlink through 5.1.6 fails to enforce API key role restrictions when issuing Mercure subscription tokens, allowing restricted keys to subscribe to all topics. Attackers with author-only or domain-only keys can access the mercure-info endpoint to receive visit data including referrer, user agent, geolocation, and full short URL objects for URLs outside their authorization boundary. | |
| Title | Shlink through 5.1.6 Mercure Token Authorization Bypass | |
| Weaknesses | CWE-863 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-17T15:01:06.137Z
Reserved: 2026-09-16T19:06:20.161Z
Link: CVE-2026-92760
Updated: 2026-09-17T15:01:01.041Z
Status : Received
Published: 2026-09-16T21:17:24.630
Modified: 2026-09-17T16:18:32.917
Link: CVE-2026-92760
No data.
OpenCVE Enrichment
Updated: 2026-09-17T21:30:18Z