Home

Description

Files or Directories Accessible to External Parties, Incorrect Permission Assignment for Critical Resource vulnerability in Hallo Welt! GmbH BlueSpice (Extension:NSFileRepo modules) allows Accessing Functionality Not Properly Constrained by ACLs, Bypassing Electronic Locks and Access Controls.This issue affects BlueSpice: from 5.1 through 5.1.3, from 5.2 through 5.2.0. HINT: Versions provided apply to BlueSpice MediaWiki releases. For Extension:NSFileRepo the affected versions are 3.0 < 3.0.5

PUBLISHED Reserved 2026-02-06 | Published 2026-03-04 | Updated 2026-03-04 | Assigner HW




MEDIUM: 6.6CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/S:P/AU:Y/RE:L

Problem types

CWE-552 Files or Directories Accessible to External Parties

CWE-732 Incorrect Permission Assignment for Critical Resource

Product status

Default status
affected

5.1 (semver)
affected

5.2 (semver)
affected

References

en.wiki.bluespice.com/...ty:Security_Advisories/BSSA-2026-02

cve.org (CVE-2026-24732)

nvd.nist.gov (CVE-2026-24732)

Download JSON