Junglewise Threat Intelligence

CVE-2026-75928: Brushfire Online Experience information disclosure via exposed database path

CVE-2026-75928 · Severity: medium · CVSS 5.3 · Published 2026-08-21

Executive brief

The Brushfire video streaming platform exposes internal database paths in HTTP requests, allowing unauthenticated attackers to discover and read sensitive information about other users without authentication. This information disclosure vulnerability could enable attackers to enumerate user accounts, access personal data, and potentially facilitate further attacks against the platform or its users.

Technical details

The vulnerability is an information disclosure issue (CWE-497) in which the Brushfire Online Experience application leaks database file paths in HTTP request/response data accessible to unauthenticated users. An attacker can remotely exploit this over the network without requiring authentication or user interaction to access sensitive system information about other platform users. The root cause is improper handling of sensitive paths in client-facing requests, allowing reconnaissance of the backend infrastructure. The vulnerability was patched on or about February 26, 2026.

Affected products

  • Brushfire Online Experience before 2026-02-26

Timeline

  • 2026-08-21: disclosed
  • 2026-02-26: patched: Fixed on or about February 26, 2026

References