CVE-2026-86777 | AlchemyCMS versions before 7.4.16 and 8.x before 8.3.6 fail to authorize access to the GET /api/nodes endpoint, allowing unauthenticated attackers to retrieve all navigation nodes. Attackers can access the endpoint without authentication to disclose restricted page names, URL paths, and internal URLs from all sites and languages.
AlchemyCMS versions before 7.4.16 and 8.x before 8.3.6 fail to authorize access to the GET /api/nodes endpoint, allowing unauthenticated attackers to retrieve all navigation nodes. Attackers can access the endpoint without authentication to disclose restricted page names, URL paths, and internal URLs from all sites and languages.
- 🔗 github.com/AlchemyCMS/alchemy_cms/security/advisorie…
- 🔗 github.com/AlchemyCMS/alchemy_cms/commit/5e2cd16a806…
- 🔗 github.com/AlchemyCMS/alchemy_cms/commit/9bdb98496d6…
- 🔗 github.com/AlchemyCMS/alchemy_cms/blob/v8.3.5/app/co…
- 🔗 github.com/AlchemyCMS/alchemy_cms/releases/tag/v8.3.…
- 🔗 github.com/AlchemyCMS/alchemy_cms/releases/tag/v7.4.…
- 🔗 github.com/AlchemyCMS/alchemy_cms
- 🔗 www.vulncheck.com/advisories/alchemycms-before-7.4.16-and-8…
```Code``` unterstützt. Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-09-05 | 2026-09-22 |
|---|---|---|
| ≥90 % | 0 | 491 |
| ≥50 % | 0 | 1475 |
| ≥10 % | 0 | 0 |
| <10 % | 300 | 0 |
CVE-2026-86777 | AlchemyCMS versions before 7.4.16 and 8.x before 8.3.6 fail to authorize access to the GET /api/nodes endpoint, allowing unauthenticated attackers to retrieve all navigation nodes. Attackers can access the endpoint without authentication to disclose restricted page names, URL paths, and internal URLs from all sites and languages.
AlchemyCMS versions before 7.4.16 and 8.x before 8.3.6 fail to authorize access to the GET /api/nodes endpoint, allowing unauthenticated attackers to retrieve all navigation nodes. Attackers can access the endpoint without authentication to
Noch keine Analyse zu CVE-2026-86777
Sei der Erste: Einschätzung, Betroffenheit, Workaround oder PoC — mit Antworten im Thread.