{"id":"PYSEC-2026-1460","summary":"Indico may disclose unauthorized user details access via legacy API","details":"### Impact\nA legacy API to retrieve user details could be misused to retrieve profile details of other users without having admin permissions due to a broken access check.\n\n### Patches\nYou should to update to [Indico 3.3.8](https://github.com/indico/indico/releases/tag/v3.3.8) as soon as possible.\nSee [the docs](https://docs.getindico.io/en/stable/installation/upgrade/) for instructions on how to update.\n\n### Workarounds\nIt is possible to restrict access to the affected API (e.g. in the webserver config) which is most likely unused anyway and thus will not break anything.\n\n### For more information\nIf you have any questions or comments about this advisory:\n\n- Open a thread in [our forum](https://talk.getindico.io/)\n- Email us privately at [indico-team@cern.ch](mailto:indico-team@cern.ch)","aliases":["CVE-2025-59034","GHSA-4269-mcfh-cp7q"],"modified":"2026-07-07T17:47:44.643622806Z","published":"2026-07-07T16:03:04.431161Z","references":[{"type":"WEB","url":"https://github.com/indico/indico/security/advisories/GHSA-4269-mcfh-cp7q"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-59034"},{"type":"PACKAGE","url":"https://github.com/indico/indico"},{"type":"WEB","url":"https://github.com/indico/indico/releases/tag/v3.3.8"},{"type":"PACKAGE","url":"https://pypi.org/project/indico"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-4269-mcfh-cp7q"}],"affected":[{"package":{"name":"indico","ecosystem":"PyPI","purl":"pkg:pypi/indico"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.3.8"}]}],"versions":["0.98-rc1","0.98.0","0.98.1","0.98.2","0.99","1.0","1.1","1.1.1","1.1.2","1.2","1.2.1","1.2.1rc10","1.2.1rc11","1.2.1rc2","1.2.1rc4","1.2.1rc5","1.2.1rc6","1.2.1rc7","1.2.1rc9","1.2.2","1.2.2rc1","1.9.11.dev10","1.9.11.dev11","1.9.11.dev12","1.9.11.dev13","1.9.11.dev14","1.9.11.dev15","1.9.11.dev16","1.9.11.dev17","1.9.11.dev3","1.9.11.dev4","1.9.11.dev6","1.9.11.dev7","1.9.11.dev8","1.9.11.dev9","2.0","2.0.1","2.0.2","2.0.3","2.0a1","2.0rc1","2.0rc2","2.1","2.1.1","2.1.10","2.1.11","2.1.2","2.1.3","2.1.4","2.1.5","2.1.6","2.1.7","2.1.8","2.1.9","2.2","2.2.1","2.2.2","2.2.3","2.2.4","2.2.5","2.2.6","2.2.7","2.2.8","2.3","2.3.1","2.3.2","2.3.3","2.3.4","2.3.5","3.0","3.0.1","3.0.2","3.0.3","3.0rc1","3.0rc2","3.1","3.1.1","3.2","3.2.1","3.2.2","3.2.3","3.2.4","3.2.5","3.2.6","3.2.7","3.2.8","3.2.9","3.3","3.3.1","3.3.2","3.3.3","3.3.4","3.3.5","3.3.6","3.3.7"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/indico/PYSEC-2026-1460.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"}]}