CVE-2026-35447

MEDIUM

NamelessMC 2.2.4 - Private Profile Access Control Bypass and Cross-Profile Writes

Title source: manual
STIX 2.1

Description

NamelessMC is website software for Minecraft servers. In version 2.2.4, the profile page (modules/Core/pages/profile.php) processes wall post submissions and replies before verifying whether the viewer is authorized to access the profile. This allows any user with the profile.post permission to write wall posts to private or blocking profiles. Additionally, the reply branch does not verify that the target wall post belongs to the current profile, enabling attackers to inject replies into arbitrary wall posts owned by other profiles via a restricted profile URL. This is patched in version 2.2.5.

References (1)

Core 1
Core References

Scores

CVSS v4 5.3
EPSS 0.0024
EPSS Percentile 14.3%
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-201
Status published
Products (1)
NamelessMC/Nameless = 2.2.4
Published Jun 02, 2026
Tracked Since Jun 02, 2026