Record summary

CVE-2026-28374 has a selected CVSS score of 4.3 (medium).

Description

Editors could delete any annotation, even those they do not have read access to. The editor user cannot create or read the annotations.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated May 14, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List8.5.0 to ≤ 11.6.14affected
11.6.14 to < 11.6.14+security-04affected
12.0.0 to ≤ 12.2.8affected
12.2.8 to < 12.2.8+security-04affected
12.3.0 to ≤ 12.3.6affected
12.3.6 to < 12.3.6+security-04affected
12.4.0 to ≤ 12.4.3affected
12.4.3 to < 12.4.3+security-02affected
13.0.0 to ≤ 13.0.1affected
13.0.1 to < 13.0.1+security-01affected

References

2