MEDIUM
CVE-2026-90939
CVSS
6.5
Description
novel-plus through 5.3.3 contains an information disclosure vulnerability in the /sys/user/list endpoint that lacks proper permission annotations. Authenticated attackers can retrieve password hashes and personal data including email addresses and phone numbers for users within their data scope, enabling offline hash cracking and account takeover.
Weakness (CWE)
CWE-862
Missing Authorization
EPSS Score
0.26%
Probability of exploitation in next 30 days
18.3th percentile
References
https://github.com/201206030/novel-plus
https://github.com/201206030/novel-plus/blob/d63c3ee394657046ebd469e263532a350a60e930/novel-admin/src/main/java/com/java2nb/system/controller/SysUserController.java
https://github.com/201206030/novel-plus/blob/d63c3ee394657046ebd469e263532a350a60e930/novel-admin/src/main/resources/mybatis/system/UserMapper.xml
https://github.com/201206030/novel-plus/releases/tag/v5.3.3
https://github.com/LinYuanyi1/cve-request-poc/blob/master/novel-plus/poc-03-user-list-password-hash-disclosure.py
https://www.vulncheck.com/advisories/novel-plus-through-5.3.3-missing-authorization-on-the-admin-sys-user-list-endpoint
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.