CVE-2026-23931: Frontend plaintext macro value enumeration via the validatate.api.exists action
Published Aug 18, 2026
·Updated
The frontend validatate.api.exists action can be exploited by authenticated users to extract plaintext user macro values leading to potential loss of confidentiality.
Event History
Aug 18, 2026
CVE Published
via MITRE·12:17 PM
Data Sourced
via MITRE·12:17 PM
RemedyDescriptionWeakness
Frequently Asked Questions
1
What level of access does an attacker need?
Authenticated users are exposed to this issue because exploitation requires an authenticated account. The impact is the disclosure of plaintext user macro values from the frontend.
2
How can I assess whether my deployment may be affected?
Review access through the frontend validatate.api.exists action and determine whether authenticated users can invoke it to retrieve plaintext user macro values. The provided information does not identify affected versions, configurations, or a workaround.