Actors
Malware
Campaigns
CVEs
Feed
Blog
Home
/
CVEs
/
CVE-2026-58593
CVE
CVE-2026-58593
View on NVD ↗
NodeBB - ActivityPub Author Spoofing via Unvalidated attributedTo Mapped to Local User
MITRE ATT&CK TTPs
4
T1068
Exploitation for Privilege Escalation
Privilege Escalation
T1078
Valid Accounts
Defense Evasion
T1189
Drive-by Compromise
Initial Access
T1650
Acquire Access
Resource Development
Source Articles
NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats
NodeBB patched eight high-severity vulnerabilities discovered by AI-powered pentesting tools, affecting all versions prior to 4.14.0. The flaws enable privilege escalation, private message access, unauthorized admin dashboard access, and cross-site scripting via malicious links in forum content. Five of the vulnerabilities are tied to federation functionality with the fediverse, and while no active exploitation has been reported, administrators are urged to upgrade to version 4.14.2 due to the critical nature of the exposures.
hacker-news
Jul 24, 2026