What is CVE-2026-72760?
A vulnerability in MISP cti-transmute exposes users' email addresses through the account following-list endpoint. In affected versions, the get_following() function includes the followed user's email in API responses, leading to unauthorized data disclosure for authenticated users. Updating to the latest patched version is strongly advised.
Azərbaycanca: MISP cti-transmute platformasında autentifikasiya olunmuş istifadəçilərin izləmə siyahısı sorğusunda digər istifadəçilərin e-poçt ünvanlarının açıqlanması zəifliyi aşkarlanıb. Təsirə məruz qalan versiyalarda get_following() funksiyası API cavabında həssas məlumatları geri qaytarır ki, bu da məxfilik pozuntusuna səbəb olur. İstifadəçilərə platformanı ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200
FAQ1
Whose email addresses can an authenticated user view in the MISP cti-transmute platform?
The vulnerability allows an authenticated user to view the email addresses of other users in their following list.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.