Impact
An improper authorization flaw in Misskey’s Server Announcements API permits attackers to retrieve sensitive announcement data that they normally cannot access, exposing personal or private information. The vulnerability stems from missing permission checks in the API (CWE‑285) and can lead to data leakage without affecting the integrity or availability of the platform.
Affected Systems
All Misskey servers with versions from 2024.5.0 up to, but not including, 2026.5.4 are vulnerable. The issue is present regardless of whether federation is enabled, affecting every instance that has not been updated to 2026.5.4 or newer.
Risk and Exploitability
The CVSS score of 6.3 indicates a moderate to high severity, and while the EPSS score is currently unavailable, the vulnerability is not listed in CISA’s KEV catalog. Attackers can exploit the flaw by making API calls to the announcements endpoint, potentially accessing data beyond their authorization level. The lack of noted active exploitation suggests the exploit vector is available but not yet widely leveraged.
OpenCVE Enrichment