Impact
This vulnerability exists in Syslifters SysReptor when a public note‑share link is accessed by an unauthenticated user. The user is automatically joined to the same collaboration group as the authenticated project members and receives collaboration metadata—including client information, connection, awareness, and deletion events—without restricting it to the shared note subtree. As a result, the attacker can see usernames, names, note identifiers, and live editing activity of notes that were not shared. The data revealed does not include the note content, and the flaw does not provide any write capability, but it does expose sensitive membership and activity information.
Affected Systems
The affected product is Syslifters SysReptor versions prior to 2026.55. Users running any release before the 2026.55 update are vulnerable; updating to 2026.55 or later resolves the issue.
Risk and Exploitability
The CVSS score of 3.5 indicates a low to moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, implying limited evidence of exploitation in the wild. The likely attack vector is external; an attacker simply needs to obtain a public note‑share link, which is typically publicly accessible. Once the link is known, the attacker can gather the disclosed metadata and identify project members and non‑shared note activity, potentially aiding reconnaissance or social engineering efforts.
OpenCVE Enrichment