Vulnerability PYSEC-2026-1460
Medium Risk
MEDIUM RISK
CVSS Score: 4.3
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
3 months ago
July 07, 2026 at 04:03 PM UTC
Indico may disclose unauthorized user details access via legacy API
0.98-rc1 - 3.3.7
0.98-rc1 - 3.3.7
Summary
Indico may disclose unauthorized user details access via legacy API
Details
Impact
A legacy API to retrieve user details could be misused to retrieve profile details of other users without having admin permissions due to a broken access check.
Patches
You should to update to Indico 3.3.8 as soon as possible. See the docs for instructions on how to update.
Workarounds
It is possible to restrict access to the affected API (e.g. in the webserver config) which is most likely unused anyway and thus will not break anything.
For more information
If you have any questions or comments about this advisory:
- Open a thread in our forum
- Email us privately at [email protected]
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
9 hours ago
Indico: Missing access check in legacy session export API
0.98-rc1 - 3.3.12 GHSA-6p4f-j8j6-463q
0.98-rc1 - 3.3.12 GHSA-6p4f-j8j6-463q
Medium Risk
9 hours ago
Indico: Cross-Site-Scripting in minutes editor
0.98-rc1 - 3.3.12 GHSA-cw24-x4mj-fw3q
0.98-rc1 - 3.3.12 GHSA-cw24-x4mj-fw3q
Medium Risk
9 hours ago
Indico: Cross-Site-Scripting in link fields
0.98-rc1 - 3.3.12 GHSA-c4wc-ggrj-jg9v
0.98-rc1 - 3.3.12 GHSA-c4wc-ggrj-jg9v
Medium Risk
3 months ago
Indico vulnerable to Cross-Site Scripting via LaTeX math code
0.98-rc1 - 3.3.7 PYSEC-2026-1461
0.98-rc1 - 3.3.7 PYSEC-2026-1461
Unknown
3 months ago
Indico vulnerability allows attackers to bulk dump user details
2.2 - 3.3.6 PYSEC-2026-1462
2.2 - 3.3.6 PYSEC-2026-1462
Impacted packages
Timeline
Published
3 months ago
July 07, 2026 at 04:03 PM UTC
Fixed (3.3.8)
1 year ago
September 10, 2025 at 03:01 PM UTC
Last Modified
3 months ago
July 07, 2026 at 05:47 PM UTC