Server Announcements API Vulnerability in Misskey Open Source Platform
CVE-2026-48115

6.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
3 August 2026

What is CVE-2026-48115?

Misskey, a popular open-source social media platform, is affected by a vulnerability in its Server Announcements API. This issue lies in insufficient permission checks, which can allow malicious actors to access sensitive data that they would typically not have permission to see. This vulnerability affects all Misskey servers running versions from 2024.5.0 to prior 2026.5.4, regardless of whether federation is enabled. Users are urged to upgrade to version 2026.5.4, where this issue has been resolved, in order to enhance their security posture.

Affected Version(s)

misskey >= 2024.5.0, < 2026.5.4

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.