CVE-2026-33954 Details
Description
LinkAce is a self-hosted archive to collect website links. In versions prior to 2.5.3, a private note attached to a non-private link can be disclosed to a different authenticated user via the web interface. The API appears to correctly enforce note visibility, but the web link detail page renders notes without applying equivalent visibility filtering. As a result, an authenticated user who is allowed to view another user's `internal` or `public` link can read that user's `private` notes attached to the link. Version 2.5.3 patches the issue.
A vulnerability in LinkAce versions prior to 2.5.3 allows private notes attached to non-private links to be disclosed to other authenticated users through the web interface. While the API correctly enforces note visibility, the web link detail page fails to apply the same filtering, leading to unauthorized access to private notes. This issue arises because the web interface directly renders link notes without considering their visibility settings. Consequently, an authenticated user who can view another user's internal or public link may also access the private notes associated with it.
Users can update to LinkAce version 2.5.3 or later, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Kovah/LinkAce/security/advisories/GHSA-88h3-cq25-vw8q | CISA-ADP | ExploitVendor Advisory |
| https://github.com/Kovah/LinkAce/security/advisories/GHSA-88h3-cq25-vw8q | [email protected] | ExploitVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-285 | Improper Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linkace linkace | < 2.5.3 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 31, 2026 | Initial Analysis | [email protected] |
| Mar 27, 2026 | New CVE Received | [email protected] |
| Mar 27, 2026 | CVE Modified | CISA-ADP |