
@lippebsd Are you sure it's CVE-2026-3321? https://www.cve.org/CVERecord?id=CVE-2026-3321
Post summary
The tweet merely questions the CVE identifier and includes a link to the CVE record, with no additional technical, exploit, or patch information.
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
A vulnerability of authorization bypass through user-controlled key in the 'console-survey/api/v1/answer/{EVENTID}/{TIMESTAMP}/' endpoint. Exploiting this vulnerability would allow an unauthenticated attacker to enumerate event IDs and obtain the complete Q&A history. This publicly exposed data may include IDs, private URLs, private messages, internal references, or other sensitive information that should only be exposed to authenticated users. In addition, the leaked content could be exploited to facilitate other malicious activities, such as reconnaissance for lateral movement, exploitation of related systems, or unauthorised access to internal applications referenced in the content of chat messages.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
STABLE
| Date | Total | Labels |
|---|
| 2026-03-30 | 1 | Disclosure1 |
| 2026-05-15 | 1 | General1 |

@lippebsd Are you sure it's CVE-2026-3321? https://www.cve.org/CVERecord?id=CVE-2026-3321
Post summary
The tweet merely questions the CVE identifier and includes a link to the CVE record, with no additional technical, exploit, or patch information.

⚠️#INCIBEaviso | Omisión de autorización en el chat Q&A de #ON24 #CVE CVE-2026-3321 https://www.incibe.es/incibe-cert/alerta-temprana/avisos/omision-de-autorizacion-en-el-chat-qa-de-on24 #AvisosDeSeguridad #TI #CNA
Post summary
Incide alert announces an authorization omission in ON24's Q&A chat, identifying CVE‑2026‑3321 as the related vulnerability.