CVE-2026-23878 is a medium-severity vulnerability affecting HotCRP conference review software versions between commits aa20ef288828b04550950cf67c831af8a525f508 and ceacd5f1476458792c44c6a993670f02c984b4a0. This flaw allows authenticated authors with at least one submission to download any document associated with any submission on the platform, leading to unauthorized information disclosure. The vulnerability has a CVSS score of 6.5 and is rated as medium severity, indicating a high potential for confidentiality impact with low attack complexity and requiring only low privileges. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.1CPE matchmatch criteria | cpe:2.3:a:hotcrp:hotcrp:3.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.