CVE-2026-107395
Deferred Deferred - Pending Action

Indico Session Metadata Exposure via Legacy API

Vulnerability report for CVE-2026-107395, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitHub, Inc.

Description

Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior to 3.3.13, an authenticated user can misuse the legacy session export API to retrieve details for a restricted session without access to that session, as long as the containing event is accessible. The missing access check can disclose session metadata such as the title, description, and conveners. This issue is fixed in version 3.3.13.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
indico indico < 3.3.13

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Indico versions before 3.3.13 allows an authenticated user to access restricted session details without proper permissions. The issue occurs in the legacy session export API, which lacks an access check. As a result, users can retrieve metadata like session titles, descriptions, and conveners for sessions they are not authorized to view, as long as the event itself is accessible.

Detection Guidance

To detect this vulnerability, check if your Indico instance is running a version prior to 3.3.13. Use the command: indico --version. If the version is below 3.3.13, the system is vulnerable. Additionally, review API logs for unauthorized access attempts to the legacy session export endpoint.

Impact Analysis

This vulnerability could lead to unauthorized disclosure of sensitive session information. Attackers with access to an event could exploit this to gather details about restricted sessions, potentially exposing confidential data such as session titles, descriptions, or conveners. This may facilitate further attacks or misuse of session information.

Compliance Impact

This vulnerability may violate compliance requirements that mandate strict access controls and protection of sensitive data. For GDPR, it could lead to unauthorized access to personal or confidential information. For HIPAA, it may compromise protected health information if session data includes such details. Organizations must address this to maintain regulatory compliance.

Mitigation Strategies

Immediately update Indico to version 3.3.13 or later. This can be done via package manager or by following the official release instructions. After updating, verify the fix by testing access to restricted sessions through the legacy API.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107395. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart