๐Ÿ” CVE Alert

CVE-2026-92760

MEDIUM 6.5

Shlink through 5.1.6 Mercure Token Authorization Bypass

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

Shlink through 5.1.6 fails to enforce API key role restrictions when issuing Mercure subscription tokens, allowing restricted keys to subscribe to all topics. Attackers with author-only or domain-only keys can access the mercure-info endpoint to receive visit data including referrer, user agent, geolocation, and full short URL objects for URLs outside their authorization boundary.

CWE CWE-863
Vendor shlinkio
Product shlink
Published Sep 16, 2026
Stay Ahead of the Next One

Get instant alerts for shlinkio shlink

Be the first to know when new medium vulnerabilities affecting shlinkio shlink are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

shlinkio / shlink
0 โ‰ค 5.1.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/shlinkio/shlink/issues/2633 github.com: https://github.com/shlinkio/shlink github.com: https://github.com/shlinkio/shlink/blob/v5.1.6/module/Rest/src/Action/MercureInfoAction.php#L26-L42 github.com: https://github.com/shlinkio/shlink-common/blob/main/src/Mercure/LcobucciJwtProvider.php#L38-L41 vulncheck.com: https://www.vulncheck.com/advisories/shlink-through-5.1.6-mercure-token-authorization-bypass

Credits

George Chen