CVE-2026-39857Disclosure(apostrophecms / apostrophecms)

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain an authorization bypass vulnerability in the choices and counts query parameters of the REST API, where these query builders execute MongoDB distinct() operations that bypass the publicApiProjection restrictions intended to limit which fields are exposed publicly. The choices and counts parameters are processed via applyBuildersSafely before the projection is applied, and MongoDB's distinct operation does not respect projections, returning all distinct values directly. The results are returned in the API response without any filtering against publicApiProjection or removeForbiddenFields. An unauthenticated attacker can extract all distinct field values for any schema field type that has a registered query builder, including string, integer, float, select, boolean, date, slug, and relationship fields. Fields protected with viewPermission are similarly exposed, and the counts variant additionally reveals how many documents have each distinct value. Both the piece-type and page REST APIs are affected. This issue has been fixed in version 4.29.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • apostrophecms

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-04-16); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
apostrophecms

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-16: 1Mentions · 2026-04-28: 1Technical Details · 2026-04-16: 1Technical Details · 2026-04-28: 104-1604-28
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • cvereports@_cvereports
    Disclosure

    CVE-2026-39857: CVE-2026-39857: Information Disclosure via Authorization Bypass in ApostropheCMS REST API ApostropheCMS versions 4.28.0 and prior contain an authorization bypass vulnerability in the REST API's 'choices' and 'counts' query builders. Th... https://cvereports.com/reports/CVE-2026-39857

    Post summary

    ApostropheCMS versions 4.28.0 and earlier are vulnerable to an authorization bypass in the REST API, enabling information disclosure via the "choices" and "counts" query builders.

    0000024
    36 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-39857 ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain an authorization bypass vulnerability in the choices and counts q… https://www.cve.org/CVERecord?id=CVE-2026-39857

    Post summary

    ApostropheCMS versions 4.28.0 and earlier suffer from an authorization bypass vulnerability (CVE-2026-39857), with no publicly disclosed PoC, exploit, or patch mentioned in the brief.

    00000105
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapostrophecmsapostrophecms---

Explore more