CVE-2026-28431General(misskey / misskey)

LOWCVSS 7.5 · HIGH

Signal is active with 6 mentions in latest observed window

Immediate actions

  • Patch misskey misskey systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Misskey is an open source, federated social media platform. All Misskey servers running versions 8.45.0 and later, but prior to 2026.3.1, contain a vulnerability that allows bad actors access to data that they ordinarily wouldn't be able to access due to insufficient permission checks and proper input validation. This vulnerability occurs regardless of whether federation is enabled or not. This vulnerability could lead to a significant data breach. This vulnerability is fixed in 2026.3.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-285

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • misskey

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 3 classified signals
  • Disclosure: 2 classified signals
  • 6 total mentions across 1 day

Affected systems

Vendors
Products
misskey

Deep dive

Activity timeline6 mentions / 1d
02356Mentions · 2026-03-09: 6Patch / Workaround · 2026-03-09: 1Technical Details · 2026-03-09: 203-09
Signal classification3 categories
General
350.0%
Disclosure
233.3%
Patch
116.7%
Referenced assets7 URLs
Full discourse6 posts
  • Open Source Security mailing list@oss_security
    Patch

    Misskey/Sharkey "extremely severe" vulnerabilities https://www.openwall.com/lists/oss-security/2026/03/09/7 These ActivityPub-based social network services (similar to Mastodon) have released updates CVE-2026-28431: Information disclosure CVE-2026-28432: Authentication bypass CVE-2026-28433: Authorization bypass

    Post summary

    Misskey/Sharkey released updates to remediate three CVEs—information disclosure, authentication bypass, and authorization bypass—without any PoC, exploit, or active exploitation reported.

    00010719
    4.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-28433 CVE-2026-28431+more https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28433

    Post summary

    The post simply lists CVE identifiers and a link to a vulnerability database without providing additional technical or exploit-related details.

    0001043
    4.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-28431 CVE-2026-28431+more https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28431

    Post summary

    The text simply lists the CVE identifier and links to a vulnerability details page without providing additional technical or exploit information.

    0001045
    4.0K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-28431: Misskey lacks proper authorizati... Unauthenticated data exfiltration via broken authz checks hits every Misskey instance since 8.45.0 - federated social n... https://zerodaysignal.com/vulnerability/CVE-2026-28431 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    A new CVE-2026-28431 affecting Misskey is disclosed, featuring unauthenticated data exfiltration due to broken authorization checks; no PoC, exploit tool, patch, or active exploitation evidence is included.

    0000093
    140 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-28431 Misskey is an open source, federated social media platform. All Misskey servers running versions 8.45.0 and later, but prior to 2026.3.1, contain a vulnerability that… https://www.cve.org/CVERecord?id=CVE-2026-28431

    Post summary

    The text announces CVE-2026-28431 affecting Misskey servers from v8.45.0 up to but excluding 2026.3.1, without providing technical details, exploit code, or mitigation information.

    0000092
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-28432 CVE-2026-28431+more https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28432 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The tweet references two CVE identifiers and provides links to a vulnerability details page and alert service, but gives no specific technical information, PoC, patch details, or evidence of exploitation.

    0000036
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmisskeymisskey---

Explore more