LOWVulnerability

CVE-2026-77135

The extension's user detail view fails to verify that a requested user record matches the configured or logged-in target, allowing any visitor with access to the Detail or List plugin to retrieve another frontend user's profile data, including name, email, date of birth and address, by supplying an arbitrary user ID.

Properties

last_source
NVD
cve_id
CVE-2026-77135
signal_observed_at
2026-09-29T00:56:27+00:00
retrieved_at
2026-09-29T00:56:27+00:00
published_at
2026-08-25T09:17:34.010
last_modified
2026-09-28T23:10:00.143

Related Entities (2)

HAS_WEAKNESS (1)

→[Weakness]Authorization Bypass Through User-Controlled Key

DESCRIBED_BY (1)

→[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-77135 — Ninja Signal Threat Intelligence | Ninja Signal