CVE-2026-30954

MEDIUM

LinkAce <=2.1.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

LinkAce is a self-hosted archive to collect website links. In 2.1.0 and earlier, the processTaxonomy() method in LinkRepository.php allows authenticated users to attach other users' private tags and lists to their own links by passing integer IDs.

Scores

CVSS v3 4.3
EPSS 0.0004
EPSS Percentile 12.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-639
Status published
Products (1)
linkace/linkace < 2.1.0
Published Mar 10, 2026
Tracked Since Mar 11, 2026