CVE-2026-28431

Misskey lacks proper authorization checks and input validation

Misskey is an open source, federated social media platform. All Misskey servers running versions 8.45.0 and later, but prior to 2026.3.1, contain a vulnerability that allows bad actors access to data that they ordinarily wouldn't be able to access due to insufficient permission checks and proper input validation. This vulnerability occurs regardless of whether federation is enabled or not. This vulnerability could lead to a significant data breach. This vulnerability is fixed in 2026.3.1.


We have discovered 10 live websites that are affected by CVE-2026-28431.

Run a Free Instant Scan




Affected Software

Product  Misskey
Category Message Boards
Vulnerable Domains10 live websites (100% of Misskey install base)
Vulnerable Versions
  • from 8.45 through 2026.3.1
Vulnerable Versions Count1 versions ( 50% of all versions)


Common Weakness Enumeration

CWE-285 Improper Authorization



Details

  • Published - Mar 9, 2026
  • Updated - Mar 10, 2026

Website Distribution by Country

Number of websites using CVE-2026-28431
United States6 websites



Germany1 websites
Japan1 websites
Russia1 websites
Singapore1 websites

Website Distribution by TLD

Number of websites using CVE-2026-28431
.io2 websites
.com1 websites
.de1 websites
.ru1 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-28431

Top websites that are affected by CVE-2026-28431. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.io United States***,***
**.*******.io United States*,***,***
********.moe United States*,***,***
******.*************.tech United States**,***,***
**.*******.xyz United States**,***,***
******.com United States**,***,***
*******.****.de Germany**,***,***
*****.********.red Singapore**,***,***
********.ru Russia**,***,***
***.pw Japan**,***,***
See full domain list

FAQ

CVE-2026-28431 is Improper Authorization in Misskey
A total of 10 websites have been identified as vulnerable to CVE-2026-28431, based on global website indexing conducted by WebTechSurvey.
The Misskey is affected by the CVE-2026-28431 vulnerability.
Misskey versions up to 2026.3.1 are vulnerable to CVE-2026-28431.
CVE-2026-28431 is resolved in version 2026.3.1 of Misskey.