Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-52077

26
FAUCET Score

CVE-2023-52077 affects Nexkey versions prior to 12.23Q4.5, allowing external applications with administrator or moderator-issued tokens to access sensitive admin APIs. This critical vulnerability (CVSS 9.8) enables unauthorized modification of server settings and compromise of object storage and email server credentials, posing a severe risk to confidentiality, integrity, and availability. While no active exploitation, public exploits, or significant community discussion have been observed, the high FAUCET Risk Score of 77/100 indicates its potential impact.

Impacted Technologies

VendorProductVersion(s)CPE
< 12.23q4.5CPE matchmatch criteria
cpe:2.3:a:nexryai:nexkey:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 3.1

8.9HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
LOW
Exploitability Score
2.3
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.69%
Probability of exploitation in next 30 days
EPSS Percentile
49.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
This CVE's current EPSS score of 0.0069 is in the 31st percentile among its peer group of 36,821 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

github_advisorypatch availablevia nvd_reference
View patch

References

github.com / mei23/misskey-v12/commit/78173e376f14fcc1987b02196f5538bf5b18225c
Patch
github.com / misskey-dev/misskey/commit/5150053275594278e9eb23e72d98b16593c4c230
Patch
github.com / nexryai/nexkey/commit/a4e4c9c47c5f84ec7ccd309bde59d4ae5d7e5a98
Patch
github.com / nexryai/nexkey/security/advisories/GHSA-pjj7-7hcj-9cpc
Vendor Advisory