Information Disclosure in Black Candy Affects Multiple Users
CVE-2026-97061

5.3MEDIUM

Key Information:

Vendor
CVE Published:
24 September 2026

What is CVE-2026-97061?

The Black Candy application up to version 3.2.1 contains a vulnerability that allows an authenticated user to exploit the search functionalities for playlists. Affected users can issue queries through the SearchController or Search::PlaylistsController without proper session scoping, resulting in the exposure of playlist names from other users' accounts. This unauthorized access could potentially lead to privacy violations, as sensitive playlist information becomes discernible to any authenticated user.

Affected Version(s)

Black Candy 0 <= 3.2.1

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Xumoyunbek Obidjonov
.