Description
Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to 4.4.3, missing Authorization in Module::settingsForm allows to view (not change) super admin-restricted module settings and leak the full module entity. Exploitation of the vulnerability is possible on behalf of an authorized user who has access to the Module View feature, which are not granted to non-admins as standard. Users should upgrade to version 4.4.3 which fixes this issue. Upgrading to a fixed version is necessary to remediate. Users unable to upgrade should revoke such privileges from users they do not trust.
Published: 2026-08-31
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Upgrade
AI Analysis

Impact

A missing authorization check in the Module::settingsForm function of Xibo CMS allows an existing authorized user to view super-admin-restricted module settings and leak the complete module entity. The flaw does not permit modification of the settings, but it exposes sensitive configuration data that should remain confidential. This is an example of an information disclosure vulnerability classified as Missing Authorization (CWE-862).

Affected Systems

All installations of the Xibo CMS product from vendor xibosignage running any version prior to 4.4.3 are affected. The vulnerability is tied to the Module View feature, which is typically enabled only for users with administrative privileges.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity, and no EPSS score is available at this time. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an authenticated user who has been granted access to the Module View functionality; exploitation requires no special privileges beyond those already assigned. Once the flaw is exploited, an attacker can obtain detailed module settings but cannot alter them. Given that privileged accounts are usually constrained, the overall impact is limited to confidentiality exposure of module configuration rather than privilege escalation or system takeover. Nonetheless, remediation is recommended to prevent potential data leakage.

Generated by OpenCVE AI on August 31, 2026 at 20:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Xibo CMS to version 4.4.3 or newer, which resolves the missing authorization check.
  • Revoke Module View privileges from users who do not require access to super-admin module settings.
  • Disable the Module View feature for non-admin accounts as an interim workaround until a patch can be applied.

Generated by OpenCVE AI on August 31, 2026 at 20:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 31 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Xibosignage
Xibosignage xibo
Vendors & Products Xibosignage
Xibosignage xibo

Mon, 31 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to 4.4.3, missing Authorization in Module::settingsForm allows to view (not change) super admin-restricted module settings and leak the full module entity. Exploitation of the vulnerability is possible on behalf of an authorized user who has access to the Module View feature, which are not granted to non-admins as standard. Users should upgrade to version 4.4.3 which fixes this issue. Upgrading to a fixed version is necessary to remediate. Users unable to upgrade should revoke such privileges from users they do not trust.
Title Xibo CMS Missing Authorization in Module::settingsForm due to PHP operator precedence
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Xibosignage Xibo
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-02T14:10:20.138Z

Reserved: 2026-06-08T14:00:43.572Z

Link: CVE-2026-52730

cve-icon Vulnrichment

Updated: 2026-09-02T14:10:16.021Z

cve-icon NVD

Status : Deferred

Published: 2026-08-31T20:17:05.427

Modified: 2026-09-09T21:09:13.080

Link: CVE-2026-52730

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T21:00:05Z

Weaknesses