CVE-2026-85605
Slink before 1.12.3 fails to properly authorize access to image comment endpoints, allowing unauthenticated attackers to read comment thread
CVSS
5.3
Medium
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Sep 4, 2026 · Last modified: Sep 4, 2026 · CWE-862
Not enough EPSS history yet.
Slink before 1.12.3 fails to properly authorize access to image comment endpoints, allowing unauthenticated attackers to read comment threads via GET /api/image/{imageId}/comments and server-sent-events subscriptions. Attackers who obtain image IDs out of band can retrieve full comment threads on public images and subscribe to live comment updates without authentication or authorization checks.
- github.comhttps://github.com/andrii-kryvoviaz/slink
- github.comhttps://github.com/andrii-kryvoviaz/slink/commit/221315b1ac51
- github.comhttps://github.com/andrii-kryvoviaz/slink/commit/fe04a7dffe8a7ed2f834f7364281a9414e394600
- github.comhttps://github.com/andrii-kryvoviaz/slink/releases/tag/v1.12.3
- github.comhttps://github.com/andrii-kryvoviaz/slink/security/advisories/GHSA-hxx4-4hwq-8258
- www.vulncheck.comhttps://www.vulncheck.com/advisories/slink-before-1.12.3-missing-authorization-on-image-comment-endpoints
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-155504.3 MED—
———The Ninja Forms - Save Progress plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.0.30. This is due to the lack of capability checks and nonce verification in the 'bulk_actions' function. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary database records from the 'wp_nf3_objects' table, such as saved submissions.59mCVE-2026-128435.4 MED—
———The LearnDash LMS plugin for WordPress is vulnerable to authorization bypass in versions 4.25.0 - 5.1.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to enroll arbitrary users in paid courses without payment verification, bypassing the entire payment system and gaining unauthorized access to premium educational content.59mCVE-2025-90498.8 HIG—
———The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'nokri_account_member_permissions' function in all versions up to, and including, 1.6.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to add new Subscriber users with employer account member permissions, who in turn can escalate privileges by updating the email address of any user, including Administrator users.59mCVE-2026-861785.4 MED—
———Pixelfed through 0.12.9 fails to validate follower status in StoryComposeController react and comment endpoints, allowing authenticated users to access follower-only stories. Attackers can enumerate sequential story IDs and submit reactions or comments to retrieve story media URLs and author information without following the account.2hCVE-2026-861778.8 HIG—
———Pterodactyl Panel before 1.14.1 fails to validate action-specific permissions in scheduled task creation, allowing subusers with only schedule.update permission to execute arbitrary console commands. Attackers can create and immediately trigger scheduled tasks that run game-server console commands, control server power state, or create backups without proper authorization checks.2hCVE-2026-861184.3 MED—
———gonic versions before 0.22.0 fail to validate administrator privileges in the startScan endpoint, allowing any authenticated user to trigger media library rescans. Attackers can repeatedly call the startScan endpoint to force CPU and I/O-intensive filesystem operations, causing denial of service on multi-user instances.3h