CVE-2026-54742: CWE-863: Incorrect Authorization in LemmyNet lemmy
CVE-2026-54742 is an authorization vulnerability in LemmyNet's lemmy software affecting versions prior to 0.19.19 and certain 1.0.0-alpha releases. It allows a community moderator to feature or unfeature posts in communities they do not moderate by exploiting insufficient verification of post ownership during federated CollectionAdd and CollectionRemove activities. This can lead to unauthorized modification of featured content across communities. The issue is fixed in versions 0.19.19 and 1.0.0-alpha.20.
AI Analysis
Technical Summary
LemmyNet's lemmy software versions from 0.19.18 up to but not including 0.19.19, and from 1.0.0-alpha.0 up to but not including 1.0.0-alpha.20, contain an incorrect authorization vulnerability (CWE-863). A community moderator can perform federated CollectionAdd and CollectionRemove activities using CollectionType::Featured to feature or unfeature posts in other communities. The authorization check verifies the actor against their own community but does not verify that the post's community_id matches the community performing the action. As a result, a moderator can manipulate featured posts in unrelated communities, affecting featured feeds and listings without proper permission. This vulnerability is addressed in versions 0.19.19 and 1.0.0-alpha.20.
Potential Impact
An attacker with community moderator privileges can manipulate featured posts in communities they do not moderate, potentially disrupting content curation and misleading users by promoting or demoting posts in unrelated communities. There is no indication of broader system compromise or data leakage. The CVSS 4.0 base score is 5.1, indicating a medium severity impact.
Mitigation Recommendations
Upgrade to LemmyNet lemmy versions 0.19.19 or later, or 1.0.0-alpha.20 or later, where this authorization issue is fixed. No other mitigation is indicated or required.
CVE-2026-54742: CWE-863: Incorrect Authorization in LemmyNet lemmy
Description
CVE-2026-54742 is an authorization vulnerability in LemmyNet's lemmy software affecting versions prior to 0.19.19 and certain 1.0.0-alpha releases. It allows a community moderator to feature or unfeature posts in communities they do not moderate by exploiting insufficient verification of post ownership during federated CollectionAdd and CollectionRemove activities. This can lead to unauthorized modification of featured content across communities. The issue is fixed in versions 0.19.19 and 1.0.0-alpha.20.
CVSS v4.0
Score 5.1medium
Affected software
LemmyNet
lemmy
pkg:cargo/github/LemmyNet/lemmyRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
LemmyNet's lemmy software versions from 0.19.18 up to but not including 0.19.19, and from 1.0.0-alpha.0 up to but not including 1.0.0-alpha.20, contain an incorrect authorization vulnerability (CWE-863). A community moderator can perform federated CollectionAdd and CollectionRemove activities using CollectionType::Featured to feature or unfeature posts in other communities. The authorization check verifies the actor against their own community but does not verify that the post's community_id matches the community performing the action. As a result, a moderator can manipulate featured posts in unrelated communities, affecting featured feeds and listings without proper permission. This vulnerability is addressed in versions 0.19.19 and 1.0.0-alpha.20.
Potential Impact
An attacker with community moderator privileges can manipulate featured posts in communities they do not moderate, potentially disrupting content curation and misleading users by promoting or demoting posts in unrelated communities. There is no indication of broader system compromise or data leakage. The CVSS 4.0 base score is 5.1, indicating a medium severity impact.
Mitigation Recommendations
Upgrade to LemmyNet lemmy versions 0.19.19 or later, or 1.0.0-alpha.20 or later, where this authorization issue is fixed. No other mitigation is indicated or required.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-15T23:12:41.964Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a86109dacd9273b4993ac9b
Added to database: 08/19/2026, 20:22:53 UTC
Last enriched: 09/11/2026, 07:33:43 UTC
Last updated: 10/03/2026, 02:46:05 UTC
Views: 88
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.