CVE-2026-77128EPSS p41.4%
CVE-2026-77128CVE-2026-77128
Description
The extension fails to enforce enable-field restrictions on a repository query parameter. An unauthenticated remote user can pass a demand-override parameter to view hidden or time-restricted events, unless the disableOverrideDemand plugin setting is active. Exploitation of this issue requires only that disableOverrideDemand is not enabled.
Scoring
| EPSS | 0.51% probability of exploitation · percentile 41.4% · 2026-10-05T12:00:23Z |
| Last modified | 2026-08-26 |