CVE-2026-47657

HIGH

HumHub Missing Authorization on Remove All Space Members Action

Title source: cna
STIX 2.1

Description

HumHub is an Open Source Enterprise Social Network. In versions 1.13.0 through 1.18.2, a missing authorization check in the Space member management controller allowed any authenticated user to trigger the removal of all members from any Space, regardless of their own role or membership in that Space. Versions 1.13.0 through 1.18.2 are affected. The vulnerability has been patched in version 1.18.3, and all users are encouraged to upgrade to this version or later immediately. No known workaround is available.

References (2)

Core 2
Core References
X_Refsource_Misc x_refsource_misc
https://github.com/humhub/humhub/pull/8163

Scores

CVSS v4 7.1
EPSS 0.0022
EPSS Percentile 12.1%
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (1)
humhub/humhub >= 1.13.0, < 1.18.3
Published Jul 21, 2026
Tracked Since Jul 21, 2026