What is CVE-2026-69115?
A missing authorization vulnerability in OpenIM Server v3.8.3 allows any authenticated user to access admin-only management API endpoints using a regular user bearer token. Immediate server update or stricter access controls are required for mitigation.
Azərbaycanca: OpenIM Server v3.8.3-də autentifikasiya olunmuş hər hansı istifadəçiyə adi bearer token ilə admin API-lərə (/user/get_users) giriş imkanı verən səlahiyyət zəifliyi aşkarlanıb. Təhlükəsizlik üçün dərhal server yenilənməli və ya giriş nəzarəti sərtləşdirilməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Does exploiting CVE-2026-69115 require authentication?
Yes, the attacker must be any authenticated user on OpenIM Server. They can access admin APIs using their own regular bearer token.
Which version of the software is affected by CVE-2026-69115?
This authorization vulnerability is detected in OpenIM Server v3.8.3.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.