CVE-2026-55417

Chevereto is a self-hosted media-sharing platform. Starting in version 3.7.5 and prior to version 4.5.4, when a user enables the private profile option, visiting their profile HTML route (`/username`) correctly returns 404. However, the `/json` AJAX listing endpoint does not apply the same check. An unauthenticated caller who knows the target's user ID can retrieve all of that user's publicly-scoped images, revealing the username (which should be private). This is patched in Chevereto v4.5.4. No known workarounds are available.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-07-07 21:17

Updated : 2026-07-10 17:56


NVD link : CVE-2026-55417

Mitre link : CVE-2026-55417

CVE.ORG link : CVE-2026-55417


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization