CVE-2026-107395

CVE-2026-107395 published: Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior to 3.3.13, an authenticated user can misuse the legacy session export API to retrieve details for a restricted session without access to t...

View full NVD advisory → ← Back to CVE watch