Indico, Missing access check in legacy session export API, GHSA-6p4f-j8j6-463q (Moderate) -DC-Oct2026-2987

Listen to this Post

The vulnerability identified in Indico’s legacy session export API stems from an insufficient authorization and broken access control mechanism when handling specific requests. Typically, Indico event management architecture enforces strict permission boundaries to ensure that access-restricted sessions within an event remain hidden or protected from unauthorized participants who do not possess the required clearance roles. However, because the legacy session export endpoint fails to properly validate the caller’s permissions against individual sessions that are more heavily protected than the surrounding parent event, an unprivileged user or attacker can bypass these intended security constraints. By querying the legacy API endpoint under the condition that the main parent event itself remains accessible, an unauthorized entity can successfully harvest sensitive internal metadata. This leaked information includes confidential session s, detailed descriptions, and convener identities that were supposed to stay restricted. The flaw highlights the inherent security risks associated with maintaining legacy API code paths where modern authorization middleware or access control decorators are omitted, leading to authorization bypasses without requiring complex exploitation chains or specialized privileges.

DailyCVE Form:

Platform: Indico
Version: 3.3.13
Vulnerability : Missing access check
Severity: Moderate
date: August 25 2026

Prediction: Available now

What Undercode Say:

Analytics

curl -X GET "https://indico.example.com/api/export/session/legacy_id" -H "Accept: application/json"
import requests
url = "https://indico.example.com/api/export/session/legacy_id"
response = requests.get(url)
if response.status_code == 200:
print("Metadata Retrieved:", response.json())

Exploit: (Educational Purposes!)

An attacker targets a publicly accessible event containing hidden or restricted sessions. By sending a crafted HTTP GET request directly to the vulnerable legacy session export API endpoint, the application processes the request without validating whether the user is authorized to view those specific nested sessions. The server then returns the metadata package containing session s, descriptions, and conveners, thereby exposing confidential conference layout details.

Protection: from this CVE

Administrators must update their Indico installations to version 3.3.13 or later immediately. As a temporary workaround if patching is delayed, web server configurations can be adjusted to explicitly restrict access to legacy API paths or the overarching event data structures should be locked down.

Impact:

Unauthorized disclosure of restricted session metadata, including s, descriptions, and conveners, affecting confidentiality across protected event configurations.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top