CVE-2026-28508 is a critical vulnerability affecting Idno social publishing platforms prior to version 1.6.4. It stems from a logic error in the API authentication, allowing unauthenticated attackers to bypass CSRF protection on the URL unfurl service. This bypass, combined with the lack of a login requirement, enables attackers to force the server to make arbitrary outbound HTTP requests, potentially accessing internal network resources or cloud metadata services and retrieving their content. The vulnerability carries a CVSS score of 9.2 (CRITICAL), indicating a severe risk with a network attack vector, low attack complexity, and no user interaction required. The potential impact is high for confidentiality, as attackers can retrieve sensitive information from internal systems. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal, suggesting low public awareness at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.6.4CPE matchmatch criteria | cpe:2.3:a:withknown:known:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.