CVE-2026-75928: Brushfire unauthenticated information disclosure
Published Aug 21, 2026
·Updated
The Brushfire platform's video content streaming application (https://online.brushfire.com) exposes database path in requests to users, allowing a remote, unauthenticated attacker to read information about other users. Fixed February 2026.
Affected Software
1 affected component
Brushfire
Event History
Aug 21, 2026
CVE Published
via MITRE·04:10 PM
Data Sourced
via MITRE·04:10 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
A remote, unauthenticated attacker can exploit it over the network. No account, privileges, or user interaction are required.
2
What information may be exposed?
The application exposes database path information in requests and may allow an attacker to read information about other users. The available data does not specify the exact user data types exposed.
3
Is there a known fix?
The issue was fixed in February 2026. The provided information does not identify a specific patched version or deployment action.