{"id":"CVE-2026-5599","title":"A user with API access and \"manage users\" permission in any venueless \nworld is able to trigger deletion of user accounts in other worlds.","summary":"A user with API access and \"manage users\" permission in any venueless \nworld is able to trigger deletion of user accounts in other worlds.","severity":"none","cwe":["CWE-653"],"published":"2026-04-05","updated":"2026-07-20","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-5599","references":[{"url":"https://github.com/venueless/venueless/security/advisories/GHSA-gwjc-33fv-2gh4","label":"655498c3-6ec5-4f0b-aea6-853b334d05a6"}],"tags":["nvd"],"epss":0.00247,"epssPercentile":0.16218,"ingestedAt":"2026-07-21T16:51:41.725Z","slug":"CVE-2026-5599","body":"## Overview\n\nA user with API access and \"manage users\" permission in any venueless \nworld is able to trigger deletion of user accounts in other worlds.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}