CVE-2026-48115
Last modified
CVE-2026-48115 is a medium-severity vulnerability rated 6.3/10 on the CVSS scale. Misskey is an open source, federated social media platform. All Misskey servers running versions 2024.5.0 and later, but prior to 2026.5.4, contain a vulnerability in the Server Announcements API where insufficient permission checks allow attackers to access limited portions of data that they normally couldn't view. EPSS estimates a 0.25% chance of exploitation in the next 30 days.
Description
Misskey is an open source, federated social media platform. All Misskey servers running versions 2024.5.0 and later, but prior to 2026.5.4, contain a vulnerability in the Server Announcements API where insufficient permission checks allow attackers to access limited portions of data that they normally couldn't view. This vulnerability occurs whether or not federation is enabled. This issue has been fixed in version 2026.5.4.
Metrics
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| misskey-dev | misskey | >= 2024.5.0, < 2026.5.4 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-48115?
How severe is CVE-2026-48115?
How do I fix CVE-2026-48115?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-4811The WPB Floating Menu & Categories for WordPress – Sticky Si…4.9
- CVE-2026-48110Russh is a Rust SSH client & server library. From version 0.…7.5
- CVE-2026-481117-Zip is a file archiver with a high compression ratio. Vers…7.1
- CVE-2026-481127-Zip is a file archiver with a high compression ratio. Vers…6.5
- CVE-2026-48113Chisel is a TCP/UDP tunnel, transported over HTTP and secure…8.5
- CVE-2026-48114Metacat is data repository software that helps researchers p…9.8
- CVE-2026-48116AnythingLLM is an application that turns pieces of content i…8.8
- CVE-2026-48117DroneAware is a drone detection platform. The centralized Dr…6.8
- CVE-2026-48119Nezha Monitoring is a self-hostable, lightweight, servers an…7.1
- CVE-2026-4812The Advanced Custom Fields (ACF) plugin for WordPress is vul…5.3
- CVE-2026-48120Kakoune is a code editor. Prior to version 2026.05.21, the b…8.6
- CVE-2026-48121@langchain/langgraph-checkpoint-mongodb provides a LangGraph…6.7
Are you affected by CVE-2026-48115?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
