SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-48115

MEDIUM · CVSS 6.3 EPSS 0.25% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-03 · Last synced 2026-09-02

CyberRota Analysis

AI-Generated

Misskey servers running versions 2024.5.0 to 2026.5.3 are vulnerable due to insufficient permission checks in the Server Announcements API, allowing unauthorized access to restricted data. This issue exists regardless of whether federation is enabled, potentially exposing sensitive information. Administrators of affected Misskey instances should prioritize upgrading to version 2026.5.4 to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-48115
Severity
MEDIUM
CVSS
6.3
EPSS
0.25%

Original NVD Description

Misskey is an open source, federated social media platform. All Misskey servers running versions 2024.5.0 and later, but prior to 2026.5.4, contain a vulnerability in the Server Announcements API where insufficient permission checks allow attackers to access limited portions of data that they normally couldn't view. This vulnerability occurs whether or not federation is enabled. This issue has been fixed in version 2026.5.4.