NodeBB federation flaw (CVE-2026-58593)
VulnerabilityFirst reported
Last updated
Happening score
H score
1
Summary
Hide ▲
Show ▼
A NodeBB federation flaw, CVE-2026-58593, lets an outside server post and send messages as any local account, including an administrator. The record was filed July 1, 2026, and no fixed version is named. The issue affects deployments with federation enabled.
Related Happenings
CISA KEV remediation deadline for SolarWinds WHD CVE-2025-40551
Public Sector Action
H score53
First: 04.02.2026 07:50
Last: 04.02.2026 07:50
Sources 1
About this happening:
CISA added CVE-2025-40551 in SolarWinds Web Help Desk to the KEV catalog and imposed federal remediation deadlines, turning a newly exploited flaw into a compl...
CISA KEV remediation deadline for SolarWinds WHD CVE-2025-40551
Public Sector Action
H score53
First: 04.02.2026 07:50
Last: 04.02.2026 07:50
Sources 1
About this happening: CISA added CVE-2025-40551 in SolarWinds Web Help Desk to the KEV catalog and imposed federal remediation deadlines, turning a newly exploited flaw into a compl...
Timeline
-
24.07.2026 10:41 2 articles · 12h ago
CVE-2026-58593 is filed for a NodeBB federation flaw
Initial DisclosureCVE-2026-58593 was filed on July 1, 2026 for a NodeBB federation flaw.
Show sources
- NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats — thehackernews.com — 24.07.2026 10:41
- NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats — thehackernews.com — 24.07.2026 10:41