Summary
All Misskey servers prior to 2026.3.1 contain a vulnerability where insufficient permission checks allow authenticated bad actors to access to limited portions of data that they normally wouldn't be able to access. This vulnerability occurs regardless of whether federation is enabled or not.
Workaround
There is no known workaround for this vulnerability.
Notes
We are intentionally limiting information at this time to protect servers that have not been patched yet. We have also fixed another critical vulnerability in 2026.3.1, so please update to the latest version of Misskey immediately.
CVE-2026-28431 consists of the following multiple security advisories. When publishing to the CVE list, it is recommended to use the one with the highest severity score, which is CVSS v4 9.2, as the basis.
Summary
All Misskey servers prior to 2026.3.1 contain a vulnerability where insufficient permission checks allow authenticated bad actors to access to limited portions of data that they normally wouldn't be able to access. This vulnerability occurs regardless of whether federation is enabled or not.
Workaround
There is no known workaround for this vulnerability.
Notes
We are intentionally limiting information at this time to protect servers that have not been patched yet. We have also fixed another critical vulnerability in 2026.3.1, so please update to the latest version of Misskey immediately.
CVE-2026-28431 consists of the following multiple security advisories. When publishing to the CVE list, it is recommended to use the one with the highest severity score, which is CVSS v4 9.2, as the basis.
GHSA-r33c-qg3g-v9cr
GHSA-cvf3-p7p2-27fh
GHSA-gg7j-c76w-8x3g