Description
The Brushfire platform's video content streaming application (https://online.brushfire.com) exposes database path in requests to users, allowing a remote, unauthenticated attacker to read information about other users. Fixed February 2026.
Published: 2026-08-21
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Brushfire platform's video content streaming application exposes its database file path in response requests, enabling a remote, unauthenticated attacker to read information about other users. This results in the disclosure of potentially sensitive user data and violates confidentiality. The vulnerability is a classic example of CWE‑497, improper handling of sensitive data paths.

Affected Systems

The affected product is Brushfire’s Online Experience video streaming application. No specific version information is listed, but the issue applies to the platform as available at https://online.brushfire.com.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate severity. EPSS is not reported, and the vulnerability is not listed in the CISA KEV database, suggesting that widespread exploitation is not currently observed. However, the flaw allows unauthenticated remote exploitation: by issuing normal API requests to the streaming service, an attacker can obtain the database path and subsequently read user data. The flaw was fixed in February 2026, so any platform still running the affected code is at risk until patched.

Generated by OpenCVE AI on August 21, 2026 at 17:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the February 2026 patch to the Brushfire online platform to remove the database path exposure.
  • If immediate patching is unavailable, restrict unauthenticated access to the affected API endpoints by applying firewall rules or network segmentation.
  • Review application configuration to confirm that no endpoint exposes sensitive system paths or files after the update.

Generated by OpenCVE AI on August 21, 2026 at 17:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Description The Brushfire platform's video content streaming application (https://online.brushfire.com) exposes database path in requests to users, allowing a remote, unauthenticated attacker to read information about other users. Fixed February 2026.
Title Brushfire unauthenticated information disclosure
Weaknesses CWE-497
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2026-08-21T16:44:39.357Z

Reserved: 2026-08-18T15:40:20.014Z

Link: CVE-2026-75928

cve-icon Vulnrichment

Updated: 2026-08-21T16:44:33.963Z

cve-icon NVD

Status : Received

Published: 2026-08-21T16:18:17.567

Modified: 2026-08-21T17:16:44.793

Link: CVE-2026-75928

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T17:45:03Z

Weaknesses
  • CWE-497

    Exposure of Sensitive System Information to an Unauthorized Control Sphere