Junglewise Threat Intelligence

CVE-2026-90939: novel-plus information disclosure in /sys/user/list endpoint

CVE-2026-90939 · Severity: medium · CVSS 6.5 · Published 2026-09-14

Technologies: 201206030 Novel-Plus. Vendors: 201206030.

Executive brief

novel-plus is a web-based content management system for managing and distributing novel content. An authenticated user can access an insufficiently protected API endpoint that exposes sensitive data—including password hashes, email addresses, and phone numbers—for other users in the system. Attackers can use this to crack passwords offline and take over accounts.

Technical details

The vulnerability is an information disclosure flaw caused by missing permission annotations on the /sys/user/list REST endpoint in novel-plus. The endpoint requires authentication but does not properly enforce role-based or data-scope restrictions, allowing any authenticated user to retrieve password hashes and personal information (email, phone) for accounts that should be restricted. An attacker with any valid account can call this endpoint to enumerate and extract credentials, which can then be attacked offline using hash-cracking techniques. Patches are available in versions after 5.3.3.

Affected products

  • 201206030 novel-plus through 5.3.3

Timeline

  • 2026-09-14: disclosed

References

Related threats