Description
novel-plus through 5.3.3 contains an information disclosure vulnerability in the /sys/user/list endpoint that lacks proper permission annotations. Authenticated attackers can retrieve password hashes and personal data including email addresses and phone numbers for users within their data scope, enabling offline hash cracking and account takeover.
Published: 2026-09-14
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure leading to Account Takeover
Action: Apply Patch
AI Analysis

Impact

The flaw is caused by missing permission annotations on the /sys/user/list endpoint in novel-plus up to version 5.3.3. An authenticated user can invoke this endpoint and receive password hashes as well as personal data such as email addresses and phone numbers. The weakness is classified as CWE-862, indicating insufficient authorization checks. The immediate effect is that an attacker can acquire credential material for offline hash cracking and potentially takeover user accounts.

Affected Systems

The vulnerable product is novel-plus, released by 201206030. The issue exists in all releases up to and including version 5.3.3. Attempts to run the endpoint in later versions are unaffected once the patch has been applied.

Risk and Exploitability

The CVSS score of 7.1 places the vulnerability in the medium‑high and the flaw is not listed in the CISA KEV catalog. Because the attack requires only valid authentication and does not need elevated privileges, any authenticated user with access to the system can exploit it. The resulting data exposure facilitates offline password cracking and enables account takeover.

Generated by OpenCVE AI on September 15, 2026 at 13:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest novel‑plus patch that adds proper authorization checks to the /sys/user/list endpoint.
  • If a patch is not yet available, restrict access to the /sys/user/list endpoint so that only administrators can call it, for example by implementing role‑based access control or network‑level restrictions.
  • Perform a code audit of all exposed endpoints to verify that authorization checks are correctly applied and that no other sensitive data is inadvertently exposed to authenticated users.

Generated by OpenCVE AI on September 15, 2026 at 13:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
Description novel-plus through 5.3.3 contains an information disclosure vulnerability in the /sys/user/list endpoint that lacks proper permission annotations. Authenticated attackers can retrieve password hashes and personal data including email addresses and phone numbers for users within their data scope, enabling offline hash cracking and account takeover.
Title novel-plus through 5.3.3 Missing Authorization on the Admin /sys/user/list Endpoint
First Time appeared Xxyopen
Xxyopen novel-plus
Weaknesses CWE-862
CPEs cpe:2.3:a:xxyopen:novel-plus:*:*:*:*:*:*:*:*
Vendors & Products Xxyopen
Xxyopen novel-plus
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Xxyopen Novel-plus
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:22:01.017Z

Reserved: 2026-09-14T11:34:24.687Z

Link: CVE-2026-90939

cve-icon Vulnrichment

Updated: 2026-09-14T14:50:50.858Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T14:17:20.240

Modified: 2026-09-23T17:17:47.630

Link: CVE-2026-90939

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T14:00:11Z

Weaknesses