CVE-2026-72914 | Mastodon up to 4.4.20/4.5.13/4.6.3 RetentionController keys/start_at/end_at improper authorization

SecurityVulns

A vulnerability identified as problematic has been detected in Mastodon up to 4.4.20/4.5.13/4.6.3. The affected element is the function Api::V1::Admin::MeasuresController/Api::V1::Admin::RetentionController. Performing a manipulation of the argument keys/start_at/end_at results in improper authorization.

This vulnerability is identified as CVE-2026-72914. The attack can be initiated remotely. There is not any exploit available.

You should upgrade the affected component.VulDB Recent EntriesRead More