CVE-2026-35447
MEDIUMNamelessMC 2.2.4 - Private Profile Access Control Bypass and Cross-Profile Writes
Title source: manualDescription
NamelessMC is website software for Minecraft servers. In version 2.2.4, the profile page (modules/Core/pages/profile.php) processes wall post submissions and replies before verifying whether the viewer is authorized to access the profile. This allows any user with the profile.post permission to write wall posts to private or blocking profiles. Additionally, the reply branch does not verify that the target wall post belongs to the current profile, enabling attackers to inject replies into arbitrary wall posts owned by other profiles via a restricted profile URL. This is patched in version 2.2.5.
References (1)
Core 1
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/NamelessMC/Nameless/security/advisories/GHSA-c9xj-rxgw-g2hq
Scores
CVSS v4
5.3
EPSS
0.0024
EPSS Percentile
14.3%
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-201
Status
published
Products (1)
NamelessMC/Nameless
= 2.2.4
Published
Jun 02, 2026
Tracked Since
Jun 02, 2026