CVE-2026-63101
HIGHOpen Event Server 1.19.1 Unauthenticated Member Roster Export via CSV Export Endpoint
Title source: cnaDescription
Open Event Server through 1.19.1 contains a missing authentication vulnerability that allows unauthenticated attackers to export the complete member roster of any group, including email addresses, names, join dates, and roles, by submitting requests to the group followers CSV export endpoint which lacks any authentication decorator. Attackers can enumerate sequential group IDs via brute-force, trigger an export via the unauthenticated POST endpoint, then poll the unauthenticated task status endpoint until completion to retrieve a download URL containing the full member CSV.
References (2)
Core 2
Core References
Exploit technical-description
exploit
Researcher Disclosure
https://github.com/geo-chen/oss/blob/main/open-event-server.md
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/open-event-server-unauthenticated-member-roster-export-via-csv-export-endpoint
Scores
CVSS v3
7.5
EPSS
0.0030
EPSS Percentile
22.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-306
Status
published
Products (1)
fossasia/open-event-server
< 1.19.1
Published
Jul 17, 2026
Tracked Since
Jul 17, 2026