What is CVE-2026-73155?
CVE-2026-73155: A vulnerability in cti-transmute allows authenticated users to add or remove emoji reactions on comments without authorization checks, exposing the `react()` handler to unauthorized access via attacker-controlled `comment_id`. Users should update to the latest patched version and enforce access controls on comment interactions.
Azərbaycanca: CVE-2026-73155: cti-transmute platformasında autentifikasiya olunmuş istifadəçilərə görmə icazəsi olmadığı şərhlərə emoji reaksiya əlavə edib silmək imkanı verən zəiflikdir. Bu, `react()` funksiyasında icazə yoxlanışının olmaması səbəbindən baş verir. İstifadəçilər dərhal platformanı ən son versiyaya yeniləməli və giriş nəzarəti yoxlamalarını tətbiq etməlidirlər.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What is the root cause of CVE-2026-73155?
The vulnerability is caused by missing authorization checks in the `react()` function, allowing authenticated users to add or remove emoji reactions on comments without proper viewing permissions.
What actions should cti-transmute users take to mitigate CVE-2026-73155?
Users should immediately update to the latest patched version and enforce access controls on comment interactions.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.