CVE-2026-86777

AlchemyCMS versions before 7.4.16 and 8.x before 8.3.6 fail to authorize access to the GET /api/nodes endpoint, allowing unauthenticated attackers to retrieve all navigation nodes. Attackers can access the endpoint without authentication to disclose restricted page names, URL paths, and internal URLs from all sites and languages.

Scoring

Severity
MEDIUM
CVSS base score
6.9
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CWE
CWE-862
Published
2026-09-09
Last modified
2026-09-09

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs