Access Control Vulnerability in Indico Event Management System by Indico
CVE-2026-107395

4.3MEDIUM

Key Information:

Vendor

Indico

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-107395?

An access control vulnerability exists in the Indico event management system that allows authenticated users to exploit the legacy session export API. This flaw enables users to retrieve sensitive metadata about restricted sessions, including titles, descriptions, and conveners, even if they do not have access to those specific sessions. The issue has been addressed in version 3.3.13, which includes necessary access checks to prevent unauthorized information disclosure.

Affected Version(s)

indico < 3.3.13

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.