CVE-2026-31956: Xibo CMS has Preview and SavedReport IDOR via disableUserCheck without controller-level authorization
Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to version 4.4.1, any authenticated user can manually construct a URL to preview campaigns/regions, and export saved reports belonging to other users. Exploitation of the vulnerability is possible on behalf of an authorized user who has any of the following privileges: Page which shows all Layouts that have been created for the purposes of Layout Management; page which shows all Campaigns that have been created for the purposes of Campaign Management; and page which shows all Reports that have been Saved. Users should upgrade to version 4.4.1 which fixes this issue. Upgrading to a fixed version is necessary to remediate.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-31956?
CVE-2026-31956 has a moderate severity level due to the potential for unauthorized access to sensitive reports.
How do I fix CVE-2026-31956?
To fix CVE-2026-31956, upgrade Xibo CMS to version 4.4.1 or later.
What type of vulnerability is CVE-2026-31956?
CVE-2026-31956 is an Insecure Direct Object Reference (IDOR) vulnerability related to user authorization.
Who is affected by CVE-2026-31956?
Any authenticated user of Xibo CMS versions prior to 4.4.1 is potentially affected by CVE-2026-31956.
What systems are impacted by CVE-2026-31956?
Xibo CMS versions up to, but not including, 4.4.1 are vulnerable to CVE-2026-31956.