CVE-2026-33284 impacts GlobaLeaks versions prior to 5.0.89, stemming from insufficient validation on the /api/support endpoint that allows arbitrary URLs to be included in support emails sent to administrators. This vulnerability carries a low CVSS score of 1.2, indicating a low severity remote attack with low complexity, primarily posing a low integrity risk. There is currently no evidence of active exploitation, public exploit code, or significant community attention, as reflected by its low EPSS score and lack of mentions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.0.89CPE matchmatch criteria | cpe:2.3:a:globaleaks:globaleaks:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.