CVE-2026-73155: cti-transmute Missing Authorization Allows Reactions to Private Comments
Affected versions of cti-transmute allow authenticated users to add or remove emoji reactions on comments without first checking whether those users are authorized to view the target comment.
The vulnerable react() handler passed an attacker-controlled commentid directly to commentsrepo.togglereaction() after only validating that the ID existed syntactically and that the requested emoji was permitted. Because comment-level visibility was not enforced, a user who could identify the ID of a private or otherwise inaccessible comment could modify reaction state on that comment despite lacking permission to access it.
The fix retrieves the target comment, rejects missing or deleted comments, retrieves its associated conversion, and enforces access.canseecomment(currentuser, comment, conversion). Unauthorized requests now receive HTTP 403.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-73155?
CVE-2026-73155 has a risk rating of 26, indicating a significant severity level.
How do I fix CVE-2026-73155?
To fix CVE-2026-73155, ensure that all reactions to comments are authorized and validate user permissions before processing the react() handler.
Who is affected by CVE-2026-73155?
Authenticated users of the cti-transmute software are affected by CVE-2026-73155 as they can react to private comments without proper authorization.
What is the impact of CVE-2026-73155?
CVE-2026-73155 allows unauthorized users to add or remove emoji reactions on private comments, potentially leading to information exposure.
When was CVE-2026-73155 published?
CVE-2026-73155 was published on August 11, 2026.