Vulnerability Description
NewsBlur before 14.5.0 contains a broken access control vulnerability that allows authenticated users to read private notification feeds by supplying arbitrary user_id values to the GET /social/interactions endpoint without ownership verification. Attackers can enumerate user_id values to access another user's follows, replies, and social activity without authorization.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/samuelclay/NewsBlur/commit/613c60b67cc46b3f4cae1dc2dfd8d717a3
- https://github.com/samuelclay/NewsBlur/releases/tag/Android_14.5.0
- https://www.vulncheck.com/advisories/newsblur-insecure-direct-object-reference-i
FAQ
What is CVE-2026-56772?
CVE-2026-56772 is a vulnerability with a CVSS score of 4.3 (MEDIUM). NewsBlur before 14.5.0 contains a broken access control vulnerability that allows authenticated users to read private notification feeds by supplying arbitrary user_id values to the GET /social/intera...
How severe is CVE-2026-56772?
CVE-2026-56772 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-56772?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.