CVE-2026-72915: Mastodon: Personally-identifying information disclosure due to incorrect access control validation
Mastodon is a free, open-source social network server based on ActivityPub. From 4.6.0-beta.1 until 4.6.4 and 4.7.0-beta.1, any logged-in local user could use the show action in app/controllers/admin/collectionscontroller.rb to access personally identifying information about another local user in a collection because the controller used the general collection policy instead of the admin collection policy namespace. The exposed data included the other user's current email address and last-used IP address. This issue is fixed in versions 4.6.4 and 4.7.0-beta.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mastodonto a version that resolves this vulnerability.Fixed in 4.6.4 - Upgrade
Upgrade
Mastodonto a version that resolves this vulnerability.Fixed in 4.7.0-beta.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72915?
CVE-2026-72915 has a high severity score of 7.5.
How do I fix CVE-2026-72915?
To fix CVE-2026-72915, update Mastodon to version 4.6.5 or later.
What type of vulnerability is CVE-2026-72915?
CVE-2026-72915 is classified as an information disclosure vulnerability.
What is affected by CVE-2026-72915?
CVE-2026-72915 affects Mastodon versions from 4.6.0-beta.1 to 4.6.4 and 4.7.0-beta.1.
Who is impacted by CVE-2026-72915?
CVE-2026-72915 can impact any logged-in local user of Mastodon who might gain unauthorized access to personally identifying information.