What is CVE-2026-65054?
A vulnerability in MediaCMS 8.2.0 allows authenticated users to disclose private media metadata of other users by adding arbitrary media tokens to their playlists without access control checks. This information disclosure occurs via a PUT request to the playlist API endpoint. Users should immediately update to the latest patched version and monitor for suspicious API requests targeting this endpoint.
Azərbaycanca: MediaCMS 8.2.0 versiyasında autentifikasiya olunmuş istifadəçilərə, öz pleylistlərinə icazəsiz media tokenləri əlavə edərək digər istifadəçilərin gizli media metadata-larını ifşa etməyə imkan verən məlumat sızması zəifliyi aşkar edilib. Bu, serverdə access control çatışmazlığı səbəbindən baş verir. İstifadəçilər dərhal proqram təminatını ən son təhlükəsizlik yeniləməsinə qədər yüksəltməli və şübhəli API sorğularını izləməlidir.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
How can an authenticated user obtain private media metadata of other users in MediaCMS 8.2.0?
An authenticated user can disclose private media metadata of other users by adding arbitrary media tokens to their playlists without access control checks.
What is recommended to mitigate the information disclosure vulnerability in MediaCMS 8.2.0?
Users should immediately update to the latest patched version and monitor for suspicious API requests targeting the playlist API endpoint.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.