CVE-2026-28374 - IDOR in Annotations API allows unprivileged users to DELETE annotation
CVE ID :CVE-2026-28374
Published : May 13, 2026, 8:16 p.m. | 51 minutes ago
Description :Editors could delete any annotation, even those they do not have read access to. The editor user cannot create or read the annotations.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : May 13, 2026, 8:16 p.m. | 51 minutes ago
Description :Editors could delete any annotation, even those they do not have read access to. The editor user cannot create or read the annotations.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...