CVE-2026-30994

HIGH

Slah <=1.5.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

Incorrect access control in the config.php component of Slah v1.5.0 and below allows unauthenticated attackers to access sensitive information, including active session credentials.

Scores

CVSS v3 7.5
EPSS 0.0006
EPSS Percentile 18.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-284
Status published
Published Apr 15, 2026
Tracked Since Apr 15, 2026