CVE-2026-72915
7.5Mastodon · Mastodon
Mastodon is vulnerable to an information exposure issue allowing unauthorized actors to access sensitive data due to a flaw in the application architecture.
Executive summary
A critical information exposure vulnerability in Mastodon allows unauthenticated remote attackers to access sensitive data, posing a significant risk to user privacy.
Vulnerability
This is an information exposure vulnerability (CWE-200) where the application fails to properly restrict access to sensitive data. The vulnerability is exploitable by unauthenticated remote attackers with no user interaction required.
Business impact
Successful exploitation of this vulnerability could lead to the unauthorized disclosure of sensitive user information or internal server data. Given the CVSS score of 7.5, this high-severity flaw threatens the confidentiality of the platform, potentially resulting in reputational damage and loss of user trust if exploited.
Remediation
Immediate Action: Administrators must update Mastodon instances to version 4.6.4 or later immediately to resolve the underlying information exposure.
Proactive Monitoring: Review server access logs for unusual patterns or unexpected requests directed at sensitive API endpoints or data repositories.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block unauthorized access attempts or suspicious traffic patterns targeting Mastodon API endpoints.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The severity of this vulnerability necessitates immediate action. Instance administrators should prioritize the deployment of the vendor-provided patch to version 4.6.4 to eliminate the risk of unauthorized data exposure.