MEDIUM

CVE-2026-90939

2026-09-14 CVSS v3.1
CVSS
6.5

Description

novel-plus through 5.3.3 contains an information disclosure vulnerability in the /sys/user/list endpoint that lacks proper permission annotations. Authenticated attackers can retrieve password hashes and personal data including email addresses and phone numbers for users within their data scope, enabling offline hash cracking and account takeover.

Weakness (CWE)

CWE-862 Missing Authorization

EPSS Score

0.26%
Probability of exploitation in next 30 days
18.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE