MEDIUMVulnerability

CVE-2026-90939

novel-plus through 5.3.3 contains an information disclosure vulnerability in the /sys/user/list endpoint that lacks proper permission annotations. Authenticated attackers can retrieve password hashes and personal data including email addresses and phone numbers for users within their data scope, enabling offline hash cracking and account takeover.

Properties

severity
MEDIUM
score
6.5
cve_id
CVE-2026-90939
signal_observed_at
2026-09-23T22:45:07+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
published_at
2026-09-14T14:17:20.240
last_modified
2026-09-23T17:17:47.630

Related Entities (2)

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Missing Authorization

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-90939 — Ninja Signal Threat Intelligence | Ninja Signal