Authorization Flaw in NamelessMC Forum Module Affects User Privacy
CVE-2026-35443
5.3MEDIUM
What is CVE-2026-35443?
NamelessMC is a popular web application designed for managing Minecraft servers. In version 2.2.4, a vulnerability exists in the forum module that compromises user privacy. While the application checks if a user can view the forum, it fails to adequately enforce topic-level permissions under certain circumstances. This allows users who should only have access to their own topics to view and modify reactions associated with other users' posts, potentially exposing sensitive interactions. Version 2.2.5 has been released to mitigate this issue by reinforcing the necessary authorization checks, ensuring that users can only interact with their own content.
Affected Version(s)
Nameless = 2.2.4
