{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-2861","assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","state":"PUBLISHED","assignerShortName":"VulDB","dateReserved":"2026-02-20T14:07:22.958Z","datePublished":"2026-02-21T06:02:07.609Z","dateUpdated":"2026-03-16T15:24:19.883Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB","dateUpdated":"2026-02-21T06:02:07.609Z"},"title":"Foswiki Changes/Viewfile/Oops information disclosure","problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-200","lang":"en","description":"Information Disclosure"}]},{"descriptions":[{"type":"CWE","cweId":"CWE-284","lang":"en","description":"Improper Access Controls"}]}],"affected":[{"vendor":"n/a","product":"Foswiki","versions":[{"version":"2.1.0","status":"affected"},{"version":"2.1.1","status":"affected"},{"version":"2.1.2","status":"affected"},{"version":"2.1.3","status":"affected"},{"version":"2.1.4","status":"affected"},{"version":"2.1.5","status":"affected"},{"version":"2.1.6","status":"affected"},{"version":"2.1.7","status":"affected"},{"version":"2.1.8","status":"affected"},{"version":"2.1.9","status":"affected"},{"version":"2.1.10","status":"affected"},{"version":"2.1.11","status":"unaffected"}],"modules":["Changes/Viewfile/Oops"]}],"descriptions":[{"lang":"en","value":"A vulnerability was detected in Foswiki up to 2.1.10. The affected element is an unknown function of the component Changes/Viewfile/Oops. The manipulation results in information disclosure. It is possible to launch the attack remotely. The exploit is now public and may be used. Upgrading to version 2.1.11 is sufficient to fix this issue. The patch is identified as 31aeecb58b64/d8ed86b10e46. Upgrading the affected component is recommended."}],"metrics":[{"cvssV4_0":{"version":"4.0","baseScore":6.9,"vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P","baseSeverity":"MEDIUM"}},{"cvssV3_1":{"version":"3.1","baseScore":5.3,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C","baseSeverity":"MEDIUM"}},{"cvssV3_0":{"version":"3.0","baseScore":5.3,"vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C","baseSeverity":"MEDIUM"}},{"cvssV2_0":{"version":"2.0","baseScore":5,"vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:OF/RC:C"}}],"timeline":[{"time":"2026-02-20T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"time":"2026-02-20T01:00:00.000Z","lang":"en","value":"VulDB entry created"},{"time":"2026-02-20T15:26:30.000Z","lang":"en","value":"VulDB entry last update"}],"credits":[{"lang":"en","value":"Jan Seebens","type":"finder"},{"lang":"en","value":"Michael Daum","type":"finder"},{"lang":"en","value":"Michael Daum (VulDB User)","type":"reporter"}],"references":[{"url":"https://vuldb.com/?id.347101","name":"VDB-347101 | Foswiki Changes/Viewfile/Oops information disclosure","tags":["vdb-entry"]},{"url":"https://vuldb.com/?ctiid.347101","name":"VDB-347101 | CTI Indicators (IOB, IOC, TTP)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/?submit.753966","name":"Submit #753966 | Foswiki 2.1.10 and before Information Disclosure","tags":["third-party-advisory"]},{"url":"https://foswiki.org/Tasks/Item15600","tags":["related"]},{"url":"https://foswiki.org/Tasks/Item15601","tags":["related"]},{"url":"https://github.com/foswiki/distro/commit/31aeecb58b64","tags":["patch"]}],"tags":["x_open-source"]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-02-23T19:27:50.200482Z","id":"CVE-2026-2861","options":[{"Exploitation":"poc"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-02-23T19:29:05.938Z"}},{"title":"CVE Program Container","references":[{"url":"http://www.openwall.com/lists/oss-security/2026/03/15/1"},{"url":"http://www.openwall.com/lists/oss-security/2026/03/16/1"},{"url":"http://www.openwall.com/lists/oss-security/2026/03/16/3"}],"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2026-03-16T15:24:19.883Z"}}]}}