Home

Description

A vulnerability was detected in Foswiki up to 2.1.10. The affected element is an unknown function of the component Changes/Viewfile/Oops. The manipulation results in information disclosure. It is possible to launch the attack remotely. The exploit is now public and may be used. Upgrading to version 2.1.11 is sufficient to fix this issue. The patch is identified as 31aeecb58b64/d8ed86b10e46. Upgrading the affected component is recommended.

PUBLISHED Reserved 2026-02-20 | Published 2026-02-21 | Updated 2026-02-23 | Assigner VulDB




MEDIUM: 6.9CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P
MEDIUM: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C
MEDIUM: 5.3CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C
5.0AV:N/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:OF/RC:C

Problem types

Information Disclosure

Improper Access Controls

Timeline

2026-02-20:Advisory disclosed
2026-02-20:VulDB entry created
2026-02-20:VulDB entry last update

Credits

Jan Seebens finder

Michael Daum finder

Michael Daum (VulDB User) reporter

References

vuldb.com/?id.347101 (VDB-347101 | Foswiki Changes/Viewfile/Oops information disclosure) vdb-entry

vuldb.com/?ctiid.347101 (VDB-347101 | CTI Indicators (IOB, IOC, TTP)) signature permissions-required

vuldb.com/?submit.753966 (Submit #753966 | Foswiki 2.1.10 and before Information Disclosure) third-party-advisory

foswiki.org/Tasks/Item15600 related

foswiki.org/Tasks/Item15601 related

github.com/foswiki/distro/commit/31aeecb58b64 patch

cve.org (CVE-2026-2861)

nvd.nist.gov (CVE-2026-2861)

Download JSON