Oct 9, 2026·5 min read·4 visits
Authenticated users can exploit a missing object-level authorization check in Indico's legacy session export API to view metadata of restricted sessions within an accessible event.
An authorization bypass vulnerability exists in the legacy session export API of Indico, an open-source event management system developed at CERN. Due to a missing object-level access check, authenticated users can bypass configuration-level restrictions to extract private session metadata (including session titles, descriptions, and list of conveners) from events that they are otherwise authorized to view.
Indico is an open-source event management system developed at CERN, designed for managing multi-track conferences, meetings, and workshops. Within its logical architecture, events serve as parent containers that group nested components, such as sessions, tracks, and contributions.
Both events and individual sessions maintain independent Access Control Lists (ACLs) to manage access permissions. It is common administrative practice to configure an event to be accessible to a wide audience while restricting specific child sessions (such as closed steering committee meetings or confidential workshops) to select users.
The legacy session export API, implemented within indico/modules/events/api.py, provides endpoints to retrieve and format session data for a given event. However, this API exposed a significant attack surface because it did not validate the authorization state of individual child sessions during retrieval.
The vulnerability is a Broken Object Level Authorization (BOLA) flaw, classified under CWE-862 (Missing Authorization). The legacy endpoint validates whether the requesting authenticated user has access to the parent event, but fails to execute granular, object-level checks on the individual child sessions within that event.
In Indico, individual database models inherit security validation capabilities. The system utilizes model-level helpers such as can_access(user) to determine whether a user possesses sufficient permissions to read the model's properties. In the vulnerable API implementation, this helper is completely bypassed during serialization.
Because the serialization system skips calling can_access() on each session within the processing loop, the API serializes metadata for all nested sessions indiscriminately. This allows any authenticated user to retrieve structural metadata of private sessions, such as their titles, descriptions, and lists of conveners, by querying the endpoint.
The vulnerability resides in the _build_sessions_api_data method within the indico/modules/events/api.py module. Below is an analysis of the vulnerable loop compared to the patched implementation.
# Vulnerable implementation in indico/modules/events/api.py
def _build_sessions_api_data(self, sessions):
"""Return an aggregated list of session blocks given the sessions."""
session_blocks = []
for session_ in sessions:
# Missing: session_.can_access(self.user) check
can_manage = self.user is not None and session_.can_manage(self.user)
session_access_list = None
serialized_session = self._serialize_session(session_)
# ... continues to append serialized data ...The patched code introduces an explicit authorization check at the beginning of each loop iteration, ensuring that inaccessible objects are skipped early in the execution flow.
# Patched implementation in indico/modules/events/api.py
def _build_sessions_api_data(self, sessions):
"""Return an aggregated list of session blocks given the sessions."""
session_blocks = []
for session_ in sessions:
# Added explicit model-level authorization check
if not session_.can_access(self.user):
continue
can_manage = self.user is not None and session_.can_manage(self.user)
session_access_list = None
serialized_session = self._serialize_session(session_)By invoking session_.can_access(self.user), the application enforces the ACL properties assigned to that specific session. If the user lacks access, the loop immediately executes continue, discarding the session from the output payload and preventing metadata serialization.
To exploit this vulnerability, an attacker must first obtain valid authentication credentials on the target Indico instance. Standard user-level access is sufficient to mount the attack, making low-privilege accounts viable vectors.
During the reconnaissance phase, the attacker identifies a target event that is visible to their account but contains restricted sessions. The event ID is typically extracted from the standard application URL during navigation.
The attacker then targets the legacy API endpoint directly by issuing an authenticated GET request to the path /api/events/<event_id>/sessions. Alternatively, other legacy API paths mapping to the vulnerable serialization helper may be invoked.
Upon receiving the request, the application checks the user's permission for the parent event. Finding it valid, the server processes the request and executes the unpatched _build_sessions_api_data method. The server returns a complete list of all sessions inside the event, disclosing sensitive metadata including session descriptions, titles, and convener identities.
The security impact of CVE-2026-107395 is limited to information disclosure, carrying a CVSS v3.1 base score of 4.3 (Medium). The vector is evaluated as CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N.
An attacker cannot alter data, execute arbitrary code, or disrupt the availability of the Indico instance. The integrity and availability impacts remain rated at None. However, the exposure of titles and descriptions of restricted sessions can leak confidential organizational plans, research topics, or internal schedules.
The exposure of convener and speaker identities also leaks organizational relationships. For installations in sensitive environments, such as research laboratories or corporate structures, the exposure of metadata from closed sessions represents a critical breach of administrative boundaries.
The primary remediation for this vulnerability is upgrading the Indico installation to version 3.3.13 or higher. This release integrates the necessary code-level authorization checks within the legacy export modules.
For administrators of standard installations, the update can be applied through the Python package manager inside the virtual environment. Executing pip install --upgrade "indico>=3.3.13" followed by running database migrations with indico db upgrade will apply the patch.
# Standard Upgrade Commands
source /opt/indico/.venv/bin/activate
pip install --upgrade "indico>=3.3.13"
indico db upgrade
supervisorctl restart indico-celery indico-uwsgiIf patching is not immediately possible, temporary mitigation can be achieved by blocking access to the legacy API endpoints. Configuring a reverse proxy like Nginx or Apache to drop external traffic to the /api/ routing prefix prevents unauthorized endpoints from being queried while maintaining main web interface functionality.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N| Product | Affected Versions | Fixed Version |
|---|---|---|
Indico CERN | < 3.3.13 | 3.3.13 |
| Attribute | Detail |
|---|---|
| CWE ID | CWE-862 (Missing Authorization) |
| Attack Vector | Network |
| CVSS v3.1 Score | 4.3 (Medium) |
| EPSS Score | N/A |
| Impact | Low Confidentiality Loss (Information Disclosure) |
| Exploit Status | None |
| CISA KEV Status | Not Listed |
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
An incomplete Server-Side Request Forgery (SSRF) validation check in Indico prior to version 3.3.13 allows authenticated event organizers to bypass outbound network restrictions. By utilizing backslash characters within crafted URLs, attackers can exploit a parser differential between the application's validator and the downstream HTTP client library to access internal network resources.
CVE-2026-107717 represents a critical prompt boundary bypass and chat role injection vulnerability in the Banks Python package (versions prior to 2.5.0). The library parses generated template outputs line-by-line, attempting to validate each segment as a JSON-serialized ChatMessage object without validating the source boundaries of the text. If an application integrates user input directly into a prompt template, a remote, unauthenticated attacker can supply multi-line inputs with structured JSON payloads. This input is then parsed as high-privilege system instructions or tool execution responses, completely hijacking downstream Large Language Model behavior.
Improper pathname limitation and link resolution (CWE-22 and CWE-59) in the banks library prior to version 2.5.1 allow local attackers to read or write arbitrary files via crafted symbolic links in the prompt directory registry.
Improper validation of dynamic class resolution within Hazelcast's Zero Config Compact Serialization allows unauthenticated clients to trigger reflective class instantiation. This flaw can be exploited to read arbitrary JVM heap or off-heap memory, crash cluster nodes, or achieve arbitrary code execution under specific classpath conditions. This issue is resolved in Hazelcast versions 5.4.5, 5.5.10, 5.6.1, and 5.7.0.
An authentication bypass vulnerability in NearForm's fast-jwt before version 6.3.4 allows attackers to replay expired tokens due to an error in the verifier's cache expiration logic. When caching is enabled, the cache TTL defaults to 10 minutes instead of honoring the token's exp claim if the token lacks an iat claim.
CVE-2026-61427 is a critical authentication bypass and improper input validation vulnerability within the Model Context Protocol (MCP) HTTP-stream server of PraisonAI. In versions prior to 4.6.78, the server lacks authentication by default and forwards client messages directly to Python tool handlers without input validation. When bound to non-localhost interfaces, this permits unauthenticated remote attackers to perform unauthorized administrative operations and execute tools.