CVE-2026-86777
Dashboard / Vulnerabilities / CVE-2026-86777
Summary: AlchemyCMS before 7.4.16 and 8.x before 8.3.6 Missing Authorization on GET /api/nodes
Details: AlchemyCMS versions before 7.4.16 and 8.x before 8.3.6 fail to authorize access to the GET /api/nodes endpoint, allowing unauthenticated attackers to retrieve all navigation nodes. Attackers can access the endpoint without authentication to disclose restricted page names, URL paths, and internal URLs from all sites and languages.
References: https://rubygems.org/gems/alchemy_cms, https://github.com/AlchemyCMS/alchemy_cms/releases/tag/v7.4.16, https://github.com/AlchemyCMS/alchemy_cms/releases/tag/v8.3.6, https://github.com/AlchemyCMS/alchemy_cms/security/advisories/GHSA-wppq-8h64-w78r, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/86xxx/CVE-2026-86777.json, https://nvd.nist.gov/vuln/detail/CVE-2026-86777, https://www.vulncheck.com/advisories/alchemycms-before-7.4.16-and-8-x-before-8.3.6-missing-authorization-on-get-api-nodes, https://github.com/AlchemyCMS/alchemy_cms/commit/5e2cd16a806c9d2df3eb6e3c889402487e0085b6, https://github.com/AlchemyCMS/alchemy_cms/commit/9bdb98496d6f17277ed05dd1abc3188f880aa554, https://github.com/AlchemyCMS/alchemy_cms, https://github.com/AlchemyCMS/alchemy_cms/blob/v8.3.5/app/controllers/alchemy/api/nodes_controller.rb
Affected packages
Package
Name:
Purl:
