LOWVulnerability

CVE-2026-77143

The frontend topic editing flow does not verify on the server side that the requesting visitor owns the topic being modified. As a result, a visitor who knows the identifier of a topic from the public forum can submit a modified update request for that topic directly and overwrite its content, without the application confirming ownership. Topic identifiers are visible in the public forum listing, and exploitation requires no privileged access or non-default configuration.

Properties

last_source
NVD
cve_id
CVE-2026-77143
signal_observed_at
2026-09-29T00:56:27+00:00
retrieved_at
2026-09-29T00:56:27+00:00
published_at
2026-08-25T09:17:35.333
last_modified
2026-09-28T23:10:00.143

Related Entities (3)

HAS_WEAKNESS (2)

→[Weakness]Missing Authorization
→[Weakness]Authorization Bypass Through User-Controlled Key

DESCRIBED_BY (1)

→[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-77143 — Ninja Signal Threat Intelligence | Ninja Signal