CVE-2026-86777
AlchemyCMS versions before 7.4.16 and 8.x before 8.3.6 fail to authorize access to the GET /api/nodes endpoint, allowing unauthenticated attackers to retrieve all navigation nodes. Attackers can access the endpoint without authentication to disclose restricted page names, URL paths, and internal URLs from all sites and languages.
Schwachstellenklasse
AlchemyCMS versions before 7.4.16 and 8.x before 8.3.6 fail to authorize access to the GET /api/nodes endpoint, allowing unauthenticated attackers to retrieve all navigation nodes. Attackers can access the endpoint without authentication to disclose restricted page names, URL paths, and internal URLs from all sites and languages.
Quellen
- https://github.com/AlchemyCMS/alchemy_cms
- https://github.com/AlchemyCMS/alchemy_cms/blob/v8.3.5/app/controllers/alchemy/api/nodes_controller.rb
- https://github.com/AlchemyCMS/alchemy_cms/commit/5e2cd16a806c9d2df3eb6e3c889402487e0085b6
- https://github.com/AlchemyCMS/alchemy_cms/commit/9bdb98496d6f17277ed05dd1abc3188f880aa554
- https://github.com/AlchemyCMS/alchemy_cms/releases/tag/v7.4.16
- https://github.com/AlchemyCMS/alchemy_cms/releases/tag/v8.3.6
Finden Sie die Schwachstelle, bevor es ein Angreifer tut.
Melden Sie sich mit GitHub an und starten Sie Ihr erstes Audit in weniger als einer Minute. Für den kostenlosen Plan ist keine Kreditkarte nötig.