Security Advisory

CVE-2026-23878

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-01-19 18:08:41
Last updated 2026-01-20 21:40:57
Assigner GitHub_M
CVSS score 6.5
State PUBLISHED

Description

HotCRP is conference review software. Starting in commit aa20ef288828b04550950cf67c831af8a525f508 and prior to commit ceacd5f1476458792c44c6a993670f02c984b4a0, authors with at least one submission on a HotCRP site could use the document API to download any documents (PDFs, attachments) associated with any submission. The problem was patched in commit ceacd5f1476458792c44c6a993670f02c984b4a0.