CVE-2026-90939: novel-plus through 5.3.3 Missing Authorization on the Admin /sys/user/list Endpoint
novel-plus through 5.3.3 contains an information disclosure vulnerability in the /sys/user/list endpoint that lacks proper permission annotations. Authenticated attackers can retrieve password hashes and personal data including email addresses and phone numbers for users within their data scope, enabling offline hash cracking and account takeover.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
novel-plusto a version that resolves this vulnerability.Fixed in 5.3.3 - Upgrade
Upgrade
novel-plusto a version that resolves this vulnerability.Fixed in through 5.3.3
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must be authenticated to novel-plus and have access to the affected endpoint. The disclosed records are limited to users within the attacker's data scope.
What information can be exposed?
The endpoint can expose user password hashes and personal data, including email addresses and phone numbers. Exposed hashes may be cracked offline and used in attempts to take over accounts.
Are unauthenticated users affected?
The available information describes exploitation by authenticated attackers. It does not indicate that an unauthenticated user can access the endpoint.
Which versions are affected?
novel-plus through version 5.3.3 is affected.