Tag Manipulation Vulnerability in LinkAce by Kovah
CVE-2026-30954

5.3MEDIUM

Key Information:

Vendor

Kovah

Status
Vendor
CVE Published:
10 March 2026

What is CVE-2026-30954?

LinkAce, a self-hosted link archiving tool developed by Kovah, contains a vulnerability in the processTaxonomy() method within LinkRepository.php. This issue permits authenticated users to associate other users' private tags and lists with their own links simply by providing integer IDs. Such unauthorized access to personal tagging functionality can lead to privacy breaches and the misuse of sensitive information stored within the platform.

Affected Version(s)

LinkAce <= 2.1.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.