Tag Manipulation Vulnerability in LinkAce by Kovah
CVE-2026-30954
5.3MEDIUM
What is CVE-2026-30954?
LinkAce, a self-hosted link archiving tool developed by Kovah, contains a vulnerability in the processTaxonomy() method within LinkRepository.php. This issue permits authenticated users to associate other users' private tags and lists with their own links simply by providing integer IDs. Such unauthorized access to personal tagging functionality can lead to privacy breaches and the misuse of sensitive information stored within the platform.
Affected Version(s)
LinkAce <= 2.1.0
