CVE-2026-33954

MEDIUM

LinkAce discloses private notesto unauthorized authenticated users via the web link detail page

Title source: cna
STIX 2.1

Description

LinkAce is a self-hosted archive to collect website links. In versions prior to 2.5.3, a private note attached to a non-private link can be disclosed to a different authenticated user via the web interface. The API appears to correctly enforce note visibility, but the web link detail page renders notes without applying equivalent visibility filtering. As a result, an authenticated user who is allowed to view another user's `internal` or `public` link can read that user's `private` notes attached to the link. Version 2.5.3 patches the issue.

Scores

CVSS v3 6.5
EPSS 0.0004
EPSS Percentile 11.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-285
Status published
Products (2)
Kovah/LinkAce < 2.5.3
linkace/linkace < 2.5.3
Published Mar 27, 2026
Tracked Since Mar 29, 2026