Misskey disclosed CVE-2026-28431, a vulnerability affecting all servers running versions 8.45.0 and later, but prior to 2026.3.1, where insufficient authorization checks combined with inadequate input validation can allow an attacker to access data they should not be able to access. The issue occurs regardless of whether federation is enabled, and the vendor warns it could result in a significant data breach; the highest-scored advisory associated with the CVE is rated CVSS v4 9.2.
There is no known workaround; administrators are advised to upgrade to Misskey 2026.3.1 to remediate. Misskey also noted it is intentionally limiting technical details to reduce risk to unpatched servers, and indicated the CVE aggregates multiple related advisories (including GHSA-r33c-qg3g-v9cr as the highest-severity item, plus additional lower-severity authorization/permission-check advisories) that are all fixed in 2026.3.1.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
The CVE entry for CVE-2026-28431 was updated with CVSS v4 vector information, CWE classification, and a reference to the GitHub Security Advisory. The record reiterated that the issue affects Misskey versions before 2026.3.1 and is fixed in that release.
A GitHub Security Advisory disclosed that Misskey versions 8.45.0 through before 2026.3.1 were vulnerable to unauthorized data access, with technical details withheld to reduce risk to unpatched servers. The umbrella CVE was identified as CVE-2026-28431, with the highest listed severity scored at CVSS v4 9.2.
Misskey addressed the authorization and input validation issues covered under CVE-2026-28431 in release 2026.3.1. The advisory states there is no workaround and urges administrators to update immediately.
A vulnerability involving insufficient authorization checks and improper input validation affected Misskey servers starting with version 8.45.0. The flaw could allow unauthorized access to data regardless of whether federation was enabled.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.