Authorization Flaw in Bugsink Error Tracking Tool
CVE-2026-47715
3.1LOW
What is CVE-2026-47715?
Bugsink, a self-hosted error tracking tool, has a project-boundary authorization vulnerability in versions prior to 2.2.0. This issue allows a logged-in user with access to one project to view event data from other projects through a URL parameter that does not validate whether the event belongs to the accessed issue. Consequently, sensitive event information, such as stack traces and breadcrumbs, can be exposed, making it essential for users to upgrade to version 2.2.0 or later to secure their data.
Affected Version(s)
bugsink < 2.2.0
