CVE-2026-27553

A low-privileged remote attacker can manipulate the schema path parameter in the /index.php/diagnostics_tab/ajax_diag_table_rows endpoint using a valid user cookie allowing disclosure of all user password hashes.

  • Published Sep 16, 2026
  • CVSS 6.5 medium
  • 0.6% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-27553 at the National Vulnerability Database