Security Advisory

CVE-2026-85605

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-09-04 14:32:07
Last updated 2026-09-04 17:45:58
Assigner VulnCheck
CVSS score 6.9
State PUBLISHED

Description

Slink before 1.12.3 fails to properly authorize access to image comment endpoints, allowing unauthenticated attackers to read comment threads via GET /api/image/{imageId}/comments and server-sent-events subscriptions. Attackers who obtain image IDs out of band can retrieve full comment threads on public images and subscribe to live comment updates without authentication or authorization checks.