๐Ÿ” CVE Alert

CVE-2026-72915

HIGH 7.5

Mastodon: Personally-identifying information disclosure due to incorrect access control validation

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

Mastodon is a free, open-source social network server based on ActivityPub. From 4.6.0-beta.1 until 4.6.4 and 4.7.0-beta.1, any logged-in local user could use the show action in app/controllers/admin/collections_controller.rb to access personally identifying information about another local user in a collection because the controller used the general collection policy instead of the admin collection policy namespace. The exposed data included the other user's current email address and last-used IP address. This issue is fixed in versions 4.6.4 and 4.7.0-beta.1.

CWE CWE-200
Vendor mastodon
Product mastodon
Published Aug 10, 2026
Stay Ahead of the Next One

Get instant alerts for mastodon mastodon

Be the first to know when new high vulnerabilities affecting mastodon mastodon are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

mastodon / mastodon
>= 4.6.0-beta.1, < 4.6.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/mastodon/mastodon/security/advisories/GHSA-hx34-2pfw-2qfj github.com: https://github.com/mastodon/mastodon/commit/467c933459c7d0e5513475b9e4888afaedfb1074 github.com: https://github.com/mastodon/mastodon/commit/930aa9fee26bf9eaefe27826fa1061288d83373b github.com: https://github.com/mastodon/mastodon/releases/tag/v4.6.4 github.com: https://github.com/mastodon/mastodon/releases/tag/v4.7.0-beta.1