Sceawere
Vulnerability Detail
CVE-2026-97261UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Notivo Unauthenticated Sensitive Data Exposure
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 3h ago
- Vendor
- VillaTheme
- Product
- Notivo
- Attack Type
- CWE-201 Insertion of Sensitive Information Into Sent Data
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated Sensitive Data Exposure in Notivo <= 1.4.2 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-09-30T13:17:37.400Z",
"pubdate": "2026-09-30T13:17:37.400Z",
"executiveSummary": "Notivo versions 1.4.2 and earlier are susceptible to an unauthenticated sensitive data exposure vulnerability.\nThis vulnerability allows remote, unauthenticated attackers to gain unauthorized access to sensitive information stored or processed by the application.\nThe flaw stems from insufficient access control mechanisms, which fail to validate the authentication status of requests directed at endpoints containing sensitive data.\nBy bypassing authentication checks, an attacker can retrieve, view, or export sensitive data without prior authorization.\nThe risk implication is high, as the exposure of sensitive data may lead to further exploitation, such as unauthorized information disclosure, privacy violations, or potential system compromise.\nNo specific user interaction or privileged credentials are required to exploit this vulnerability, making it accessible to any actor capable of reaching the target endpoint over the network.",
"technicalDetails": "The vulnerability resides within the application's request handling logic, specifically where access control checks are either absent or improperly implemented for sensitive API endpoints or data retrieval functions.\nIn Notivo versions 1.4.2 and earlier, the application fails to enforce authentication requirements at the controller or middleware layer for these specific resources.\nAn attacker can exploit this by crafting HTTP requests targeting the vulnerable endpoints and sending them directly to the server.\nBecause the application does not verify the session or authentication token of the incoming request, the server processes the request as if it were legitimate and returns the requested sensitive data in the HTTP response body.\nThis constitutes an Insecure Direct Object Reference (IDOR) or a missing function-level access control scenario, depending on the specific implementation of the vulnerable endpoint.\nThe attack flow proceeds as follows: First, the attacker identifies the publicly accessible or improperly protected API endpoints that return sensitive information. Second, the attacker issues a GET, POST, or other HTTP method request to these endpoints without providing valid authentication headers or session cookies. Third, the server, lacking the necessary enforcement checks, retrieves the requested data from the backend store or memory and serves it directly to the attacker.\nThe impact of successful exploitation is significant, potentially leading to the leakage of user data, configuration details, or other sensitive information depending on the nature of the data handled by the vulnerable endpoints. This exposure occurs without leaving trace evidence of authenticated access, complicating incident response and forensic analysis. The vulnerability is exploitable over the network, making it a critical concern for internet-facing instances of Notivo."
}