CVE-2026-53698: Medium severity Silverpeas Silverpeas vulnerability

Published Jun 10, 2026
·
Updated

Silverpeas through 6.4.6 mishandles the "Personal space" feature that is selected when no componentId is set.

Affected Software

1 affected component
Silverpeas Silverpeas<=6.4.6

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Require a non-empty componentId be provided; do not allow selection of the 'Personal space' option when componentId is not set.

    Silverpeas 'Personal space' feature componentId required = true
  2. Compensating control

    Disable or restrict access to the 'Personal space' feature (the option selected when no componentId is set) until an official vendor fix is available; limit use to trusted administrators or internal networks.

Event History

Jun 10, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2026-53698?

The severity of CVE-2026-53698 is medium with a score of 6.5.

2

What risks are associated with CVE-2026-53698?

CVE-2026-53698 poses a risk level of 38, indicating potential vulnerabilities in handling the 'Personal space' feature.

3

How do I fix CVE-2026-53698?

To fix CVE-2026-53698, update Silverpeas to version 6.4.6 or later, which addresses the mishandling issue.

4

What kind of vulnerability is CVE-2026-53698?

CVE-2026-53698 is a vulnerability related to improper handling of the 'Personal space' feature in Silverpeas.

5

When was CVE-2026-53698 published?

CVE-2026-53698 was published on June 10, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203