CVE-2026-92760

Shlink through 5.1.6 fails to enforce API key role restrictions when issuing Mercure subscription tokens, allowing restricted keys to subscribe to all topics. Attackers with author-only or domain-only keys can access the mercure-info endpoint to receive visit data including referrer, user agent, geolocation, and full short URL objects for URLs outside their authorization boundary.
Configurations

No configuration.

History

17 Sep 2026, 16:18

Type Values Removed Values Added
References () https://github.com/shlinkio/shlink/issues/2633 - () https://github.com/shlinkio/shlink/issues/2633 -

16 Sep 2026, 21:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-09-16 21:17

Updated : 2026-09-17 16:18


NVD link : CVE-2026-92760

Mitre link : CVE-2026-92760

CVE.ORG link : CVE-2026-92760


JSON object : View

Products Affected

No product.

CWE
CWE-863

Incorrect Authorization