CVE-2023-26428

MEDIUM

Open-Xchange AppSuite Backend - Information Disclosure via Snippet ID

Title source: llm
STIX 2.1

Description

Attackers can successfully request arbitrary snippet IDs, including E-Mail signatures of other users within the same context. Signatures of other users could be read even though they are not explicitly shared. We improved permission handling when requesting snippets that are not explicitly shared with other users. No publicly available exploits are known.

Scores

CVSS v3 6.5
EPSS 0.0032
EPSS Percentile 55.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-639
Status published
Products (2)
open-xchange/open-xchange_appsuite_backend 7.10.6 (2 CPE variants)
open-xchange/open-xchange_appsuite_backend < 7.10.6
Published Jun 20, 2023
Tracked Since Feb 18, 2026