CVE-2026-108164
Received Received - Intake

Insecure Direct Object Reference in Open Source Social Network Exposes Private Message Attachments

Vulnerability report for CVE-2026-108164, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: VulnCheck

Description

Open Source Social Network (OSSN) through 10.1 contains an insecure direct object reference vulnerability in components/OssnMessages/ossn_com.php that allows authenticated users to read other users' private message attachments. Attackers can request the /messages/attachment/{guid} route with sequential or guessed file GUIDs to retrieve attachments from private conversations without sender or recipient verification.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
opensource-socialnetwork opensource-socialnetwork 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-108164 is an Insecure Direct Object Reference (IDOR) vulnerability in Open Source Social Network (OSSN) versions up to 10.1. It allows authenticated users to access private message attachments of other users by exploiting the /messages/attachment/{guid} endpoint without proper authorization checks. Attackers can retrieve attachments by guessing or sequentially requesting file GUIDs.

Detection Guidance

To detect this vulnerability, monitor network traffic for unauthorized access to the /messages/attachment/{guid} endpoint. Check server logs for repeated requests to this route with sequential or guessed GUIDs. Use tools like curl to test if authenticated users can access attachments not belonging to them by requesting arbitrary file IDs.

Impact Analysis

This vulnerability allows unauthorized users to access private message attachments, leading to privacy violations and exposure of sensitive data such as confidential documents or images. Attackers can automate the process to steal attachments by enumerating file IDs.

Compliance Impact

This vulnerability likely violates privacy regulations like GDPR and HIPAA by exposing private user data without authorization. It undermines data protection requirements for confidentiality and user consent.

Mitigation Strategies

Apply the official patch from the OSSN GitHub repository commit 2e9733d which adds ownership checks for file downloads. Ensure all instances of OSSN are updated to the latest version. Restrict access to the /messages/attachment/{guid} endpoint and implement rate limiting to prevent enumeration attacks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108164. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart