Information Disclosure in Black Candy Affects Multiple Users
CVE-2026-97061
5.3MEDIUM
What is CVE-2026-97061?
The Black Candy application up to version 3.2.1 contains a vulnerability that allows an authenticated user to exploit the search functionalities for playlists. Affected users can issue queries through the SearchController or Search::PlaylistsController without proper session scoping, resulting in the exposure of playlist names from other users' accounts. This unauthorized access could potentially lead to privacy violations, as sensitive playlist information becomes discernible to any authenticated user.
Affected Version(s)
Black Candy 0 <= 3.2.1
