Access Control Vulnerability in Indico Event Management System by Indico
CVE-2026-107395
4.3MEDIUM
What is CVE-2026-107395?
An access control vulnerability exists in the Indico event management system that allows authenticated users to exploit the legacy session export API. This flaw enables users to retrieve sensitive metadata about restricted sessions, including titles, descriptions, and conveners, even if they do not have access to those specific sessions. The issue has been addressed in version 3.3.13, which includes necessary access checks to prevent unauthorized information disclosure.
Affected Version(s)
indico < 3.3.13
