What is CVE-2026-23931?
This vulnerability (CVE-2026-23931) allows authenticated users to extract plaintext user macro values via the `validatate.api.exists` action, leading to a potential loss of confidentiality. Access to this functionality should be immediately restricted on affected systems.
Azərbaycanca: Bu kritik zəiflik (CVE-2026-23931) autentifikasiya olunmuş istifadəçilərə `validatate.api.exists` əməliyyatı vasitəsilə digər istifadəçilərin makro dəyərlərini açıq mətn şəklində əldə etməyə imkan verir, nəticədə məxfilik itkisinə səbəb olur. Təsirə məruz qalan sistemlərdə dərhal bu funksiyaya giriş məhdudlaşdırılmalıdır.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Through which action can CVE-2026-23931 be exploited?
This vulnerability is exploited through the `validatate.api.exists` action.
What is the impact of successful exploitation of CVE-2026-23931?
Successful exploitation allows authenticated users to extract plaintext user macro values, leading to a potential loss of confidentiality.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.