LOWVulnerability

CVE-2026-77144

The frontend management plugin attributed a newly created event to the submitting user's organizer record only when the request supplied no organizer of its own. The accompanying permission check confirmed only that the submitting user held any organizer role. A user with frontend event management access could therefore create an event that is attributed to another organizer.

Properties

last_source
NVD
cve_id
CVE-2026-77144
signal_observed_at
2026-09-29T00:56:27+00:00
retrieved_at
2026-09-29T00:56:27+00:00
published_at
2026-08-25T09:17:35.510
last_modified
2026-09-28T23:10:00.143

Related Entities (2)

HAS_WEAKNESS (1)

→[Weakness]Improperly Controlled Modification of Dynamically-Determined Object Attributes

DESCRIBED_BY (1)

→[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-77144 — Ninja Signal Threat Intelligence | Ninja Signal