---
id: CVE-2026-5599
title: |-
  A user with API access and "manage users" permission in any venueless 
  world is able to trigger deletion of user accounts in other worlds.
summary: |-
  A user with API access and "manage users" permission in any venueless 
  world is able to trigger deletion of user accounts in other worlds.
severity: none
cwe:
  - CWE-653
published: '2026-04-05'
updated: '2026-07-20'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-5599'
references:
  - url: >-
      https://github.com/venueless/venueless/security/advisories/GHSA-gwjc-33fv-2gh4
    label: 655498c3-6ec5-4f0b-aea6-853b334d05a6
tags:
  - nvd
epss: 0.00247
epssPercentile: 0.16251
ingestedAt: '2026-07-21T16:51:41.725Z'
---

## Overview

A user with API access and "manage users" permission in any venueless 
world is able to trigger deletion of user accounts in other worlds.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
