CVE-2026-32736Disclosure(hytalemodding / wiki)

LOWCVSS 4.3 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Hytale Modding Wiki is a free service for Hytale mods to host their documentation & wikis. An Insecure Direct Object Reference (IDOR) vulnerability in versions of the wiki prior to 1.0.0 exposes mod authors' personal information - including full names and email addresses - to any authenticated user who visits a mod page. Any user who creates an account can access sensitive author details by simply navigating to a mod's page via its slug. Version 1.0.0 fixes the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wiki

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Affected systems

Products
wiki

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-19: 3Technical Details · 2026-03-19: 303-19
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-32736 The Hytale Modding Wiki is a free service for Hytale mods to host their documentation & wikis. An Insecure Direct Object Reference (IDOR) vulnerability in versions of… https://www.cve.org/CVERecord?id=CVE-2026-32736

    Post summary

    The text announces a new IDOR vulnerability (CVE-2026-32736) affecting the Hytale Modding Wiki, with no details on exploitation, mitigation, or PoC provided.

    00000145
    56.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-32736 Insecure Direct Object Reference (IDOR) Vulnerability in Hytale Modding Wiki https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-32736

    Post summary

    A new IDOR vulnerability (CVE‑2026‑32736) affecting the Hytale Modding Wiki has been disclosed, but no proof‑of‑concept, exploit, active exploitation, patch, or false‑positive information is provided.

    0000060
    4.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-32736 - Hytale Modding Wiki has Insecure Direct Object Reference / GDPR PII Exposure Intel Report: https://ift.tt/BCdYKbX

    Post summary

    A new CVE (CVE-2026-32736) has been disclosed, pointing out an insecure direct object reference that could expose GDPR PII on the Hytale Modding Wiki; no PoC, exploit, or patch information is provided.

    0000061
    335 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphytalemoddingwiki---

Explore more