CVE-2026-28352Medium· 6.5▾ SunlitIndico has a missing access check in the event series management API
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.3%
The API endpoint used to manage event series is missing an access check, allowing unauthenticated/unauthorized access to this endpoint.
The impact of this is limited to:
That this vulnerability does NOT allow unauthorized access to events (beyond the basic metadata mentioned above), nor any kind of tampering with user-visible data in events.
Developers should to update to Indico 3.3.11 as soon as possible. See the docs for instructions on how to update.
If there are any questions or comments about this advisory:
indico < 3.3.11Upgrade to a patched release:
indico 3.3.11Connected by shared product, vendor, weakness, or advisory.
CVE-2026-33046HighIndico discloses local files resulting in Remote Code Execution through LaTeX injection
CVE-2026-25739Medium· 5.4Indico Affected by Cross-Site-Scripting via material uploads
CVE-2026-25738MediumIndico has Server-Side Request Forgery (SSRF) in multiple places
CVE-2025-53640MediumIndico vulnerability allows attackers to bulk dump user details
CVE-2025-59035Medium· 4.6Indico vulnerable to Cross-Site Scripting via LaTeX math code
CVE-2025-59034Medium· 4.3Indico may disclose unauthorized user details access via legacy API