The API endpoint used to manage event series is missing an access check, allowing unauthenticated/unauthorized access to this endpoint.
The impact of this is limited to:
That this vulnerability does NOT allow unauthorized access to events (beyond the basic metadata mentioned above), nor any kind of tampering with user-visible data in events.
Developers should to update to Indico 3.3.11 as soon as possible. See the docs for instructions on how to update.
If there are any questions or comments about this advisory:
{
"nvd_published_at": "2026-02-27T21:16:19Z",
"github_reviewed_at": "2026-03-01T01:24:27Z",
"github_reviewed": true,
"cwe_ids": [
"CWE-306"
],
"severity": "MODERATE"
}