DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-107395: CVE-2026-107395: Missing Authorization in Indico Legacy Session Export API

CVE-2026-107395: Missing Authorization in Indico Legacy Session Export API

Vulnerability ID: CVE-2026-107395
CVSS Score: 4.3
Published: 2026-10-08

An authorization bypass vulnerability exists in the legacy session export API of Indico, an open-source event management system developed at CERN. Due to a missing object-level access check, authenticated users can bypass configuration-level restrictions to extract private session metadata (including session titles, descriptions, and list of conveners) from events that they are otherwise authorized to view.

TL;DR

Authenticated users can exploit a missing object-level authorization check in Indico's legacy session export API to view metadata of restricted sessions within an accessible event.


Technical Details

  • CWE ID: CWE-862 (Missing Authorization)
  • Attack Vector: Network
  • CVSS v3.1 Score: 4.3 (Medium)
  • EPSS Score: N/A
  • Impact: Low Confidentiality Loss (Information Disclosure)
  • Exploit Status: None
  • CISA KEV Status: Not Listed

Affected Systems

  • Indico Event Management System
  • Indico: < 3.3.13 (Fixed in: 3.3.13)

Code Analysis

Commit: 524e8e9

Fix missing model authorization check during legacy session serialization loop

@@ -755,6 +755,8 @@ def _build_sessions_api_data(self, sessions):
         """Return an aggregated list of session blocks given the sessions."""
         session_blocks = []
         for session_ in sessions:
+            if not session_.can_access(self.user):
+                continue
             can_manage = self.user is not None and session_.can_manage(self.user)
             session_access_list = None
             serialized_session = self._serialize_session(session_)
Enter fullscreen mode Exit fullscreen mode

Commit: 1c8f920

Bumps the version to 3.3.13-dev

Mitigation Strategies

  • Upgrade Indico to version 3.3.13 or newer.
  • Restrict reverse-proxy access to legacy export API endpoints (/api/events/*/sessions) using Nginx or Apache configuration policies.
  • Audit event permissions to ensure overall parent event visibility is restricted if it contains highly sensitive internal metadata.

Remediation Steps:

  1. Access the Indico server console and switch to the application user.
  2. Activate the virtual environment: source /opt/indico/.venv/bin/activate.
  3. Upgrade the package: pip install --upgrade "indico>=3.3.13".
  4. Perform database schema checks: indico db upgrade.
  5. Restart application processes: supervisorctl restart indico-celery indico-uwsgi.

References


Read the full report for CVE-2026-107395 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)