{"id":"CVE-2022-26595","details":"Liferay Portal 7.3.7, 7.4.0, and 7.4.1, and Liferay DXP 7.2 fix pack 13, and 7.3 fix pack 2 does not properly check user permission when accessing a list of sites/groups, which allows remote authenticated users to view sites/groups via the user's site membership assignment UI.","aliases":["BIT-liferay-2022-26595","GHSA-822f-jfpg-hg7h"],"modified":"2026-09-05T03:30:24.394945142Z","published":"2022-04-19T12:52:20Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/26xxx/CVE-2022-26595.json","cna_assigner":"mitre"},"references":[{"type":"WEB","url":"https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2022-26595-unauthorized-access-to-site-group-list"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/26xxx/CVE-2022-26595.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-26595"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/liferay/liferay-portal","events":[{"introduced":"29b73b9b896c7d44fb5d1800a402698c303d1cf6"},{"last_affected":"548f3899675d89749f92b7623d25e27d0c4691c7"}],"database_specific":{"cpe":["cpe:2.3:a:liferay:liferay_portal:7.3.7:*:*:*:*:*:*:*","cpe:2.3:a:liferay:liferay_portal:7.4.0:*:*:*:*:*:*:*","cpe:2.3:a:liferay:liferay_portal:7.4.1:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"7.3.7"},{"last_affected":"7.3.7"},{"introduced":"7.4.0"},{"last_affected":"7.4.0"},{"introduced":"7.4.1"},{"last_affected":"7.4.1"}],"source":"CPE_STRING"}}],"versions":["7.3.7","7.4.0","7.4.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-26595.json"}}],"schema_version":"1.9.0"}