Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 04 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 04 Sep 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Slink before 1.12.3 fails to properly authorize access to image comment endpoints, allowing unauthenticated attackers to read comment threads via GET /api/image/{imageId}/comments and server-sent-events subscriptions. Attackers who obtain image IDs out of band can retrieve full comment threads on public images and subscribe to live comment updates without authentication or authorization checks. | |
| Title | Slink before 1.12.3 Missing Authorization on Image Comment Endpoints | |
| First Time appeared |
Slinkapp
Slinkapp slink |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:slinkapp:slink:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Slinkapp
Slinkapp slink |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-04T17:45:58.601Z
Reserved: 2026-09-04T11:00:28.731Z
Link: CVE-2026-85605
Updated: 2026-09-04T17:45:55.570Z
Status : Received
Published: 2026-09-04T15:17:41.233
Modified: 2026-09-04T18:18:04.047
Link: CVE-2026-85605
No data.
OpenCVE Enrichment
Updated: 2026-09-04T15:30:07Z