CVE-2026-28352

Source
https://cve.org/CVERecord?id=CVE-2026-28352
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-28352.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-28352
Aliases
Published
2026-02-27T21:01:45.740Z
Modified
2026-03-03T01:23:54.475792Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
Indico missing access check in event series management API
Details

Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. In versions prior to 3.3.11, the API endpoint used to manage event series is missing an access check, allowing unauthenticated/unauthorized access to this endpoint. The impact of this is limited to getting the metadata (title, category chain, start/end date) for events in an existing series, deleting an existing event series, and modifying an existing event series. This vulnerability does NOT allow unauthorized access to events (beyond the basic metadata mentioned above), nor any kind of tampering with user-visible data in events. Version 3.3.11 fixes the issue. As a workaround, use the webserver to restrict access to the series management API endpoint.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/28xxx/CVE-2026-28352.json",
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-306"
    ]
}
References

Affected packages

Git / github.com/indico/indico

Affected ranges

Type
GIT
Repo
https://github.com/indico/indico
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v0.*
v0.97-rc1
v0.97-rc2
v0.97.0
v0.97b
v0.97b2
v0.98-rc1
v0.98.1
v0.98.2
v0.98.3
v0.99.0
v1.*
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.2-latest
v1.2.0
v1.9.1
v1.9.11.dev10
v1.9.11.dev11
v1.9.11.dev12
v1.9.11.dev13
v1.9.11.dev14
v1.9.11.dev15
v1.9.11.dev16
v1.9.11.dev17
v1.9.11.dev18
v1.9.11.dev3
v1.9.11.dev6
v1.9.11.dev7
v1.9.11.dev8
v1.9.11.dev9
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.9
v2.*
v2.0
v2.0.1
v2.0.2
v2.0.3
v2.0a1
v2.0rc1
v2.0rc2
v2.1
v2.1.1
v2.1.10
v2.1.11
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.1.7
v2.1.7+docs
v2.1.8
v2.1.9
v2.1a1
v2.1a2
v2.1a3
v2.1b1
v2.1rc1
v2.1rc2
v2.1rc3
v2.1rc4
v2.1rc5
v2.1rc6
v2.2
v2.2+docs
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.2.8
v2.2.8+archived
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.5+archived
v3.*
v3.0
v3.0.1
v3.0.2
v3.0.3
v3.0.3+archived
v3.0rc1
v3.0rc2
v3.1
v3.1.1
v3.1.1+archived
v3.2
v3.2.1
v3.2.2
v3.2.3
v3.2.4
v3.2.5
v3.2.6
v3.2.6+docs
v3.2.7
v3.2.8
v3.2.9
v3.3
v3.3.1
v3.3.10
v3.3.2
v3.3.3
v3.3.4
v3.3.5
v3.3.6
v3.3.7
v3.3.8
v3.3.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-28352.json"