CVE-2026-107395: Missing Authorization in Indico Legacy Session Export API
Vulnerability ID: CVE-2026-107395
CVSS Score: 4.3
Published: 2026-10-08
An authorization bypass vulnerability exists in the legacy session export API of Indico, an open-source event management system developed at CERN. Due to a missing object-level access check, authenticated users can bypass configuration-level restrictions to extract private session metadata (including session titles, descriptions, and list of conveners) from events that they are otherwise authorized to view.
TL;DR
Authenticated users can exploit a missing object-level authorization check in Indico's legacy session export API to view metadata of restricted sessions within an accessible event.
Technical Details
- CWE ID: CWE-862 (Missing Authorization)
- Attack Vector: Network
- CVSS v3.1 Score: 4.3 (Medium)
- EPSS Score: N/A
- Impact: Low Confidentiality Loss (Information Disclosure)
- Exploit Status: None
- CISA KEV Status: Not Listed
Affected Systems
- Indico Event Management System
-
Indico: < 3.3.13 (Fixed in:
3.3.13)
Code Analysis
Commit: 524e8e9
Fix missing model authorization check during legacy session serialization loop
@@ -755,6 +755,8 @@ def _build_sessions_api_data(self, sessions):
"""Return an aggregated list of session blocks given the sessions."""
session_blocks = []
for session_ in sessions:
+ if not session_.can_access(self.user):
+ continue
can_manage = self.user is not None and session_.can_manage(self.user)
session_access_list = None
serialized_session = self._serialize_session(session_)
Commit: 1c8f920
Bumps the version to 3.3.13-dev
Mitigation Strategies
- Upgrade Indico to version 3.3.13 or newer.
- Restrict reverse-proxy access to legacy export API endpoints (/api/events/*/sessions) using Nginx or Apache configuration policies.
- Audit event permissions to ensure overall parent event visibility is restricted if it contains highly sensitive internal metadata.
Remediation Steps:
- Access the Indico server console and switch to the application user.
- Activate the virtual environment:
source /opt/indico/.venv/bin/activate. - Upgrade the package:
pip install --upgrade "indico>=3.3.13". - Perform database schema checks:
indico db upgrade. - Restart application processes:
supervisorctl restart indico-celery indico-uwsgi.
References
- GHSA-6p4f-j8j6-463q: Missing Authorization in Legacy API in Indico
- CVE-2026-107395 CVE Record
- Indico Version 3.3.13 Release Notes
Read the full report for CVE-2026-107395 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)