Back to overview

CVE-2026-47657

HIGH
7.1
CVSS 4.0
Description
HumHub is an Open Source Enterprise Social Network. In versions 1.13.0 through 1.18.2, a missing authorization check in the Space member management controller allowed any authenticated user to trigger the removal of all members from any Space, regardless of their own role or membership in that Space. Versions 1.13.0 through 1.18.2 are affected. The vulnerability has been patched in version 1.18.3, and all users are encouraged to upgrade to this version or later immediately. No known workaround is available.

Metadata

CVE ID
CVE-2026-47657
State
PUBLISHED
Assigner
GitHub_M
Reserved
2026-05-19 21:10 UTC
Published
2026-07-21 17:50 UTC
Last updated
2026-07-21 18:36 UTC
Primary CWE
CWE-862
CWE-862: Missing Authorization
Vendor / Product
humhub / humhub
Sources
cve.org  ·  NVD

Severity & Metrics

7.1 HIGH CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
humhub humhub >= 1.13.0, < 1.18.3
Weakness (CWE)
CWESourceDescription
CWE-862 cna CWE-862: Missing Authorization
CVSS scores (1)
ScoreSeverityVersionSourceVector
7.1 HIGH 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
References (2)
Back to overview