A high-severity access control flaw tracked as CVE-2026-63101 allows unauthenticated attackers to export complete group member rosters from Open Event Server through version 1.19.1. The vulnerability affects the group followers CSV export workflow and can expose sensitive membership data including email addresses, names, join dates, and user roles.
Attackers can brute-force sequential group IDs, submit requests to an unauthenticated CSV export POST endpoint, poll an unauthenticated task-status endpoint, and retrieve a download URL for the generated file. The issue is remotely exploitable and has been rated CVSS 3.1 7.5 and CVSS 4.0 8.7. Recommended remediation is to upgrade to Open Event Server 1.19.2 or later and enforce authentication checks on the affected endpoints.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
A missing authentication vulnerability affecting Open Event Server through version 1.19.1 was publicly disclosed. The flaw allows unauthenticated attackers to export group member rosters via the CSV export workflow, exposing data such as email addresses, names, join dates, and roles.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcevulncheck.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.