CVE-2026-47657 Details
Description
HumHub is an Open Source Enterprise Social Network. In versions 1.13.0 through 1.18.2, a missing authorization check in the Space member management controller allowed any authenticated user to trigger the removal of all members from any Space, regardless of their own role or membership in that Space. Versions 1.13.0 through 1.18.2 are affected. The vulnerability has been patched in version 1.18.3, and all users are encouraged to upgrade to this version or later immediately. No known workaround is available.
A vulnerability in HumHub versions 1.13.0 through 1.18.2 allows any authenticated user to remove all members from any Space. This issue arises from a missing authorization check in the Space member management controller, enabling users to act regardless of their role or membership status within the Space. The vulnerability has been patched in version 1.18.3, and users are advised to upgrade immediately. No known workaround is available.
Users should upgrade to HumHub version 1.18.3 or later. No workaround is available.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 21, 2026CISA-ADP
Assessed Jul 21, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/humhub/humhub/pull/8163 | [email protected] | Issue TrackingVendor |
| https://github.com/humhub/humhub/security/advisories/GHSA-hj67-5q6h-j7c2 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| HumHub | >= 1.13.0, <= 1.18.2 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 21, 2026 | CVE Modified | CISA-ADP |
| Jul 21, 2026 | New CVE Received | [email protected] |
Volerion