MEDIUMVulnerability

CVE-2026-85392

Peppermint through 0.5.5 contains an authorization bypass vulnerability in the GET /api/v1/auth/user/:id/logout endpoint that allows authenticated attackers to delete sessions for any user by supplying arbitrary user IDs. Attackers can forcibly log out any user including administrators by calling the logout handler with another user's ID, since the endpoint performs no authorization checks to verify the caller owns the target account.

Properties

severity
MEDIUM
score
4.3
cve_id
CVE-2026-85392
signal_observed_at
2026-09-15T21:20:01+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
published_at
2026-09-03T19:17:30.970
last_modified
2026-09-09T20:20:21.673

Related Entities (2)

HAS_WEAKNESS (1)

[Weakness]Authorization Bypass Through User-Controlled Key

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-85392 — Ninja Signal Threat Intelligence | Ninja Signal