Authorization Flaw in Bugsink Error Tracking Tool
CVE-2026-47715

3.1LOW

Key Information:

Vendor

Bugsink

Status
Vendor
CVE Published:
26 May 2026

What is CVE-2026-47715?

Bugsink, a self-hosted error tracking tool, has a project-boundary authorization vulnerability in versions prior to 2.2.0. This issue allows a logged-in user with access to one project to view event data from other projects through a URL parameter that does not validate whether the event belongs to the accessed issue. Consequently, sensitive event information, such as stack traces and breadcrumbs, can be exposed, making it essential for users to upgrade to version 2.2.0 or later to secure their data.

Affected Version(s)

bugsink < 2.2.0

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.