Description
Misskey is an open source, federated social media platform. All Misskey servers running versions 2024.5.0 and later, but prior to 2026.5.4, contain a vulnerability in the Server Announcements API where insufficient permission checks allow attackers to access limited portions of data that they normally couldn't view. This vulnerability occurs whether or not federation is enabled. This issue has been fixed in version 2026.5.4.
Published: 2026-08-03
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper authorization flaw in Misskey’s Server Announcements API permits attackers to retrieve sensitive announcement data that they normally cannot access, exposing personal or private information. The vulnerability stems from missing permission checks in the API (CWE‑285) and can lead to data leakage without affecting the integrity or availability of the platform.

Affected Systems

All Misskey servers with versions from 2024.5.0 up to, but not including, 2026.5.4 are vulnerable. The issue is present regardless of whether federation is enabled, affecting every instance that has not been updated to 2026.5.4 or newer.

Risk and Exploitability

The CVSS score of 6.3 indicates a moderate to high severity, and while the EPSS score is currently unavailable, the vulnerability is not listed in CISA’s KEV catalog. Attackers can exploit the flaw by making API calls to the announcements endpoint, potentially accessing data beyond their authorization level. The lack of noted active exploitation suggests the exploit vector is available but not yet widely leveraged.

Generated by OpenCVE AI on August 4, 2026 at 09:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to Misskey version 2026.5.4 or newer
  • If immediate update is not possible, temporarily disable the announcements API or limit its usage to strictly authenticated users
  • As a workaround, enforce explicit permission checks in the API code before returning announcement data

Generated by OpenCVE AI on August 4, 2026 at 09:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Misskey
Misskey misskey
Vendors & Products Misskey
Misskey misskey

Mon, 03 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description Misskey is an open source, federated social media platform. All Misskey servers running versions 2024.5.0 and later, but prior to 2026.5.4, contain a vulnerability in the Server Announcements API where insufficient permission checks allow attackers to access limited portions of data that they normally couldn't view. This vulnerability occurs whether or not federation is enabled. This issue has been fixed in version 2026.5.4.
Title Misskey: Improper Authorization in the Announcements API
Weaknesses CWE-285
References
Metrics cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-08-05T14:24:48.433Z

Reserved: 2026-05-20T18:46:58.289Z

Link: CVE-2026-48115

cve-icon Vulnrichment

Updated: 2026-08-05T14:24:45.708Z

cve-icon NVD

Status : Received

Published: 2026-08-03T22:16:49.593

Modified: 2026-08-05T15:16:51.267

Link: CVE-2026-48115

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T09:45:06Z

Weaknesses