Vulnerability Description
Access control settings for forum post custom fields are not applied to the JSON output type, leading to an ACL violation vector an information disclosure
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Stackideas | Easydiscuss | >= 1.0.0, <= 5.0.15 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-21626?
CVE-2026-21626 is a vulnerability with a CVSS score of 7.5 (HIGH). Access control settings for forum post custom fields are not applied to the JSON output type, leading to an ACL violation vector an information disclosure
How severe is CVE-2026-21626?
CVE-2026-21626 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-21626?
Check the references section above for vendor advisories and patch information. Affected products include: Stackideas Easydiscuss.