CVE-2026-77166: Low severity vulnerability
Published Sep 21, 2026
·Updated
The emoji field in the page emoji update endpoint does not properly validate user input. By injecting long text and line breaks, the sidebar layout becomes broken and can hide other items.
Event History
Sep 21, 2026
CVE Published
via MITRE·03:25 PM
Data Sourced
via MITRE·03:25 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access and user interaction are required for exploitation?
The CVSS vector indicates an attacker needs high privileges and requires user interaction. The attack can be conducted over the network with low attack complexity.