SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-77128

MEDIUM · CVSS 6.3 EPSS 0.37% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-25 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The vulnerability allows unauthenticated remote users to bypass enable-field restrictions on a repository query parameter, potentially exposing hidden or time-restricted events if the disableOverrideDemand plugin setting is not activated. This could lead to unauthorized access to sensitive information. Organizations using the affected extension should prioritize addressing this issue, particularly those that have not enabled the disableOverrideDemand setting.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-77128
Severity
MEDIUM
CVSS
6.3
EPSS
0.37%

Original NVD Description

The extension fails to enforce enable-field restrictions on a repository query parameter. An unauthenticated remote user can pass a demand-override parameter to view hidden or time-restricted events, unless the disableOverrideDemand plugin setting is active. Exploitation of this issue requires only that disableOverrideDemand is not enabled.