Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-54676— Scoold: GET /api/posts/{id}/answers leaks private-space replies when personal API tokens are enabled

Quick assessment

Affected
Erudika scoold
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Scoold 是一个面向团队的问答与知识共享平台。在 1.69.0 版本之前,拥有个人 API 令牌的用户可以从他们无权访问的私有空间中获取问题的回复。其原因在于 方法(位于 中)在返回 接口的数据前,未执行 权限检查。当 和 均设置为 ,且令牌持有者知道或通过枚举获取到某个私有问题的标识符时,该漏洞可被触发。在这种情况下,问题详情接口可能会拒绝访问,但回复接口却会返回私有的回复内容,从而泄露团队或项目的机密讨论。该问题已在 1.69.0 版本中修复。

CVSS 6.5 · Medium EPSS 0.40% · P32

Possible ATT&CK Techniques 1 AI

T1212 · Exploitation for Credential Access

Affected Version Matrix 1

VendorProduct Version RangeStatus
Erudika scoold < 1.69.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-54676

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Scoold: GET /api/posts/{id}/answers leaks private-space replies when personal API tokens are enabled
Source: CVE Program / CVE List V5
Vulnerability Description
Scoold is a Q&A and a knowledge sharing platform for teams. Prior to 1.69.0, users with personal API tokens can retrieve replies from questions in private spaces they cannot access because src/main/java/com/erudika/scoold/api/ApiController.java in ApiController.getPostReplies() does not apply canAccessSpace before returning data from GET /api/posts/{id}/answers. The issue is reachable when scoold.api_user_access_enabled and scoold.api_enabled are true and a token holder knows or enumerates a private question identifier. Under those conditions, the question endpoint can deny access while the answers endpoint returns the private reply bodies, exposing confidential team or project discussions. This issue is fixed in version 1.69.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Erudika scoold < 1.69.0 -

II. Public POCs for CVE-2026-54676

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-54676

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-54676 (1)

Vendor Advisories for CVE-2026-54676 (1)

Vendor Pages for CVE-2026-54676 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-54676

No comments yet


Leave a comment