MediaCMS 8.2.0 contains an information disclosure vulnerability that allows authenticated users to expose private media metadata belonging to other… (CVE-2026-65054)
MediaCMS version 8.2.0 contains an information disclosure vulnerability that allows authenticated users to access private media metadata of other users. This occurs because the playlist API endpoint lacks proper access control checks when adding media tokens, enabling attackers to bypass ownership validation. Exploitation involves issuing a PUT request with arbitrary media tokens to a playlist, then retrieving private fields such as title, description, view count, like count, file size, author username, and encoding status from the playlist details.
AI Analysis
Technical Summary
The vulnerability in MediaCMS 8.2.0 (CVE-2026-65054) is an information disclosure issue caused by missing access control checks on the playlist API endpoint. Authenticated users can add arbitrary media tokens to their playlists without verifying ownership or state, which allows them to retrieve private metadata of media owned by other users. This includes sensitive information such as media titles, descriptions, view and like counts, file sizes, author usernames, and encoding statuses. The flaw corresponds to CWE-863 (Incorrect Authorization). No patch or official remediation has been indicated in the available data.
Potential Impact
An attacker with authentication can expose private media metadata belonging to other users, potentially violating user privacy and confidentiality. The disclosed information includes media titles, descriptions, view and like counts, file sizes, author usernames, and encoding statuses. There is no indication of further privilege escalation or remote code execution. The impact is limited to unauthorized information disclosure.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to the playlist API endpoint to trusted users only and monitor for suspicious activity involving media token manipulation. Avoid sharing authentication credentials with untrusted parties. Follow vendor updates closely for any forthcoming patches or official mitigations.
MediaCMS 8.2.0 contains an information disclosure vulnerability that allows authenticated users to expose private media metadata belonging to other… (CVE-2026-65054)
Description
MediaCMS version 8.2.0 contains an information disclosure vulnerability that allows authenticated users to access private media metadata of other users. This occurs because the playlist API endpoint lacks proper access control checks when adding media tokens, enabling attackers to bypass ownership validation. Exploitation involves issuing a PUT request with arbitrary media tokens to a playlist, then retrieving private fields such as title, description, view count, like count, file size, author username, and encoding status from the playlist details.
CVSS v4.0
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in MediaCMS 8.2.0 (CVE-2026-65054) is an information disclosure issue caused by missing access control checks on the playlist API endpoint. Authenticated users can add arbitrary media tokens to their playlists without verifying ownership or state, which allows them to retrieve private metadata of media owned by other users. This includes sensitive information such as media titles, descriptions, view and like counts, file sizes, author usernames, and encoding statuses. The flaw corresponds to CWE-863 (Incorrect Authorization). No patch or official remediation has been indicated in the available data.
Potential Impact
An attacker with authentication can expose private media metadata belonging to other users, potentially violating user privacy and confidentiality. The disclosed information includes media titles, descriptions, view and like counts, file sizes, author usernames, and encoding statuses. There is no indication of further privilege escalation or remote code execution. The impact is limited to unauthorized information disclosure.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to the playlist API endpoint to trusted users only and monitor for suspicious activity involving media token manipulation. Avoid sharing authentication credentials with untrusted parties. Follow vendor updates closely for any forthcoming patches or official mitigations.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-363p-gjpv-2pxq
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-65054"]
- Ecosystems
- []
- Database Specific Severity
- HIGH
- Cvss Version
- 4.0
Threat ID: 6a600aa59c2644c7f8fdfe7c
Added to database: 07/22/2026, 00:11:17 UTC
Last enriched: 07/22/2026, 00:40:19 UTC
Last updated: 07/31/2026, 19:23:00 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.