CVE-2026-72915
Received Received - Intake

Information Disclosure in Mastodon

Vulnerability report for CVE-2026-72915, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-10

Last updated on: 2026-08-10

Assigner: GitHub, Inc.

Description

Mastodon is a free, open-source social network server based on ActivityPub. From 4.6.0-beta.1 until 4.6.4 and 4.7.0-beta.1, any logged-in local user could use the show action in app/controllers/admin/collections_controller.rb to access personally identifying information about another local user in a collection because the controller used the general collection policy instead of the admin collection policy namespace. The exposed data included the other user's current email address and last-used IP address. This issue is fixed in versions 4.6.4 and 4.7.0-beta.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-10
Last Modified
2026-08-10
Generated
2026-08-11
AI Q&A
2026-08-11
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
mastodon mastodon From 4.6.0-beta.1 (inc) to 4.6.4 (exc)
mastodon mastodon From 4.7.0-beta.1 (inc)
mastodon mastodon 4.6.4
mastodon mastodon 4.7.0-beta.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Mastodon allowed any logged-in local user to access another user's personally identifying information through the admin collections feature. The issue occurred because the system used a general collection policy instead of a stricter admin policy, exposing email addresses and IP addresses.

Impact Analysis

If you are a Mastodon user, your email address and IP address could be exposed to other local users. This may lead to privacy breaches, targeted attacks, or misuse of your personal data.

Compliance Impact

This vulnerability likely violates privacy regulations like GDPR and HIPAA by exposing personally identifiable information without proper authorization. Organizations using affected Mastodon versions may face compliance violations and legal consequences.

Mitigation Strategies

Upgrade Mastodon to version 4.6.4 or 4.7.0-beta.1 or later to address the vulnerability. Review admin access logs for unauthorized collection access attempts between versions 4.6.0-beta.1 and 4.6.4.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-72915. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart