VulnerabilityModified
CVE-2026-2861
A vulnerability was detected in Foswiki up to 2.1.10.
MEDIUM 5.5EPSS 0.46%
Does this matter?
Lower severity and a low EPSS score (0.46%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability was detected in Foswiki up to 2.1.10. The affected element is an unknown function of the component Changes/Viewfile/Oops. The manipulation results in information disclosure. It is possible to launch the attack remotely. The exploit is now public and may be used. Upgrading to version 2.1.11 is sufficient to fix this issue. The patch is identified as 31aeecb58b64/d8ed86b10e46. Upgrading the affected component is recommended.
- CVSS 4.0
- 5.5 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.46% probability · 38th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200, CWE-284
- Affected
- foswiki/foswiki
- Source
- cna@vuldb.com
References
- https://foswiki.org/Tasks/Item15600Permissions Required
- https://foswiki.org/Tasks/Item15601Permissions Required
- https://github.com/foswiki/distro/commit/31aeecb58b64Patch
- https://vuldb.com/?ctiid.347101Permissions Required, VDB Entry
- https://vuldb.com/?id.347101Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.753966Third Party Advisory, VDB Entry
- http://www.openwall.com/lists/oss-security/2026/03/15/1
- http://www.openwall.com/lists/oss-security/2026/03/16/1
- http://www.openwall.com/lists/oss-security/2026/03/16/3
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.