CVE-2026-47657
HIGHHumHub Missing Authorization on Remove All Space Members Action
Title source: cnaDescription
HumHub is an Open Source Enterprise Social Network. In versions 1.13.0 through 1.18.2, a missing authorization check in the Space member management controller allowed any authenticated user to trigger the removal of all members from any Space, regardless of their own role or membership in that Space. Versions 1.13.0 through 1.18.2 are affected. The vulnerability has been patched in version 1.18.3, and all users are encouraged to upgrade to this version or later immediately. No known workaround is available.
References (2)
Core 2
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/humhub/humhub/security/advisories/GHSA-hj67-5q6h-j7c2
X_Refsource_Misc x_refsource_misc
https://github.com/humhub/humhub/pull/8163
Scores
CVSS v4
7.1
EPSS
0.0022
EPSS Percentile
12.1%
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-862
Status
published
Products (1)
humhub/humhub
>= 1.13.0, < 1.18.3
Published
Jul 21, 2026
Tracked Since
Jul 21, 2026