Junglewise Threat Intelligence

CVE-2026-33398: NamelessMC improper authorization in forum get_quotes endpoint

CVE-2026-33398 · Severity: info · CVSS 7.1 · Published 2026-06-02

Technologies: NamelessMC. Vendors: NamelessMC.

Executive brief

NamelessMC is a popular website software used by Minecraft server communities to manage forums and user accounts. A security flaw allows any logged-in user to bypass privacy settings and read messages in restricted areas, such as private staff-only forums. This could lead to the exposure of sensitive administrative discussions or private member data.

Technical details

An improper authorization vulnerability (CWE-285) exists in the `get_quotes.php` module of NamelessMC version 2.2.4. While the standard topic view enforces Access Control Lists (ACLs), the `get_quotes` endpoint only verifies that a user is logged in before fetching post content via an attacker-supplied `post` ID. Because the backend helper in `Forum.php` fails to validate forum or topic-level permissions, a low-privileged user can enumerate post IDs to leak content and author metadata from restricted, hidden, or staff-only forums. This issue is resolved in version 2.2.5.

Affected products

  • NamelessMC NamelessMC 2.2.4

Timeline

  • 2026-05-31: advisory: GitHub Security Advisory published
  • 2026-06-02: disclosed: CVE published to NVD

References

Related threats