Authorization Flaw in NamelessMC Forum Module Affects User Privacy
CVE-2026-35443

5.3MEDIUM

Key Information:

Vendor

Namelessmc

Status
Vendor
CVE Published:
2 June 2026

What is CVE-2026-35443?

NamelessMC is a popular web application designed for managing Minecraft servers. In version 2.2.4, a vulnerability exists in the forum module that compromises user privacy. While the application checks if a user can view the forum, it fails to adequately enforce topic-level permissions under certain circumstances. This allows users who should only have access to their own topics to view and modify reactions associated with other users' posts, potentially exposing sensitive interactions. Version 2.2.5 has been released to mitigate this issue by reinforcing the necessary authorization checks, ensuring that users can only interact with their own content.

Affected Version(s)

Nameless = 2.2.4

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.