The extension fails to enforce enable-field restrictions on a repository query parameter. An unauthenticated remote user can pass a demand-override parameter to view hidden or time-restricted events, unless the disableOverrideDemand plugin setting is active. Exploitation of this issue requires only that disableOverrideDemand is not enabled.
CVSS
No CVSS.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-25 09:17
Updated : 2026-08-26 17:13
NVD link : CVE-2026-77128
Mitre link : CVE-2026-77128
CVE.ORG link : CVE-2026-77128
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
