NodeBB has patched eight high-severity vulnerabilities in its forum platform after public disclosure of flaws that could expose administrator functions, private messages, private categories, and user content. The issues affected all versions before 4.14.0, and included unauthorized admin dashboard access by a regular member, post takeover, vote manipulation, and a cross-site scripting issue tied to NodeBB’s translation pass. Public reporting said exploit code was released alongside the disclosure, increasing the urgency for administrators to remediate affected systems.
Five of the eight flaws were linked to NodeBB’s federation code, leaving fresh version 4 deployments with federation enabled by default exposed to the full set of issues, while many upgraded version 3 instances without federation enabled were exposed to only three. NodeBB had already shipped fixes across releases in May, June, and July, and administrators were urged to upgrade to 4.14.2. No CVEs were assigned to the eight disclosed bugs and no in-the-wild exploitation was reported, although coverage noted a separate related federation issue tracked as CVE-2026-58593.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
NodeBB had already fixed the eight vulnerabilities across releases issued in May, June, and July before the public disclosure. Administrators were advised to upgrade to version 4.14.2.
The eight vulnerabilities were publicly disclosed along with exploit code, revealing that five of the flaws were in NodeBB's federation code and that fresh version 4 installs with federation enabled were exposed to all eight issues. The disclosure also noted that no CVEs were assigned to these flaws and no in-the-wild exploitation had been reported.
Aikido Security reported finding eight high-severity vulnerabilities in the NodeBB forum platform, including issues that could expose admin access, private messages, private categories, and enable code injection. The findings affected NodeBB versions prior to 4.14.0.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcethehackernews.com
Open sourceaikido.dev
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.