📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global insider Education HIGH 2h Global supply_chain Software Development and Technology HIGH 7h Global apt Government/Critical Infrastructure CRITICAL 9h Global vulnerability Enterprise Software / Data Analytics CRITICAL 10h Global vulnerability Artificial Intelligence and Technology HIGH 13h Global general Technology and Artificial Intelligence MEDIUM 16h Global general Technology and Artificial Intelligence HIGH 17h Global vulnerability Higher Education CRITICAL 1d Global data_breach Government HIGH 1d Global supply_chain Software Development and Open Source Communities CRITICAL 1d Global insider Education HIGH 2h Global supply_chain Software Development and Technology HIGH 7h Global apt Government/Critical Infrastructure CRITICAL 9h Global vulnerability Enterprise Software / Data Analytics CRITICAL 10h Global vulnerability Artificial Intelligence and Technology HIGH 13h Global general Technology and Artificial Intelligence MEDIUM 16h Global general Technology and Artificial Intelligence HIGH 17h Global vulnerability Higher Education CRITICAL 1d Global data_breach Government HIGH 1d Global supply_chain Software Development and Open Source Communities CRITICAL 1d Global insider Education HIGH 2h Global supply_chain Software Development and Technology HIGH 7h Global apt Government/Critical Infrastructure CRITICAL 9h Global vulnerability Enterprise Software / Data Analytics CRITICAL 10h Global vulnerability Artificial Intelligence and Technology HIGH 13h Global general Technology and Artificial Intelligence MEDIUM 16h Global general Technology and Artificial Intelligence HIGH 17h Global vulnerability Higher Education CRITICAL 1d Global data_breach Government HIGH 1d Global supply_chain Software Development and Open Source Communities CRITICAL 1d
Vulnerabilities

CVE-2026-28352

Medium
Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. In versions prior to 3.3.11, the API endpoint used to manage event series is missing an
CWE-306 — Weakness Type
Published: Feb 27, 2026  ·  Modified: Feb 28, 2026  ·  Source: NVD
CVSS v3
6.5
🔗 NVD Official
📄 Description (English)

Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. In versions prior to 3.3.11, the API endpoint used to manage event series is missing an access check, allowing unauthenticated/unauthorized access to this endpoint. The impact of this is limited to getting the metadata (title, category chain, start/end date) for events in an existing series, deleting an existing event series, and modifying an existing event series. This vulnerability does NOT allow unauthorized access to events (beyond the basic metadata mentioned above), nor any kind of tampering with user-visible data in events. Version 3.3.11 fixes the issue. As a workaround, use the webserver to restrict access to the series management API endpoint.

🤖 AI Executive Summary

Indico event management system versions prior to 3.3.11 contain an access control vulnerability in the API endpoint for managing event series, allowing unauthenticated users to view event metadata, delete series, and modify series. The vulnerability is limited to series-level operations and does not permit unauthorized access to event data or user-visible information.

📄 Description (Arabic)

تحتوي نقطة نهاية API لإدارة سلسلة الأحداث في Indico على فجوة في التحقق من الوصول، مما يسمح بالوصول غير المصرح به إلى العمليات الحساسة. يمكن للمهاجمين عرض البيانات الوصفية للأحداث وحذف أو تعديل سلسلة الأحداث دون المصادقة المناسبة. لا تؤثر الثغرة على بيانات الأحداث الفعلية أو معلومات المستخدم المرئية.

🤖 ملخص تنفيذي (AI)

نظام إدارة الأحداث Indico في الإصدارات السابقة للإصدار 3.3.11 يحتوي على ثغرة في التحكم بالوصول في نقطة نهاية API لإدارة سلسلة الأحداث، مما يسمح للمستخدمين غير المصرح لهم بعرض بيانات الأحداث الوصفية وحذف السلسلة وتعديلها. تقتصر الثغرة على عمليات على مستوى السلسلة ولا تسمح بالوصول غير المصرح به إلى بيانات الأحداث أو المعلومات المرئية للمستخدم.

🤖 AI Intelligence Analysis Analyzed: May 12, 2026 00:04
🇸🇦 Saudi Arabia Impact Assessment
Saudi Relevance: high
🏢 Affected Saudi Sectors
government telecom energy banking
🎯 MITRE ATT&CK Techniques
⚖️ Saudi Risk Score (AI)
6.0
/ 10.0
🔧 Remediation Steps (English)
Upgrade Indico to version 3.3.11 or later immediately. As an interim measure, configure webserver access restrictions to the series management API endpoint (/api/events/series) to allow only authenticated and authorized users. Implement network-level access controls and monitor API logs for unauthorized access attempts.
🔧 خطوات المعالجة (العربية)
قم بترقية Indico إلى الإصدار 3.3.11 أو أحدث على الفور. كإجراء مؤقت، قم بتكوين قيود الوصول على خادم الويب لنقطة نهاية API إدارة السلسلة (/api/events/series) للسماح فقط للمستخدمين المصرح لهم والمصادقين. تطبيق عناصر التحكم في الوصول على مستوى الشبكة ومراقبة سجلات API لمحاولات الوصول غير المصرح به.
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
5.1 5.2 5.3
🔵 SAMA CSF
AC-2 AC-3 AC-4
🟡 ISO 27001:2022
A.9.1.1 A.9.2.1 A.9.4.1
📊 CVSS Score
6.5
/ 10.0 — Medium
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredN — None / Network
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityL — Low / Local
IntegrityL — Low / Local
AvailabilityN — None / Network
📋 Quick Facts
Severity Medium
CVSS Score6.5
CWECWE-306
EPSS0.04%
Exploit No
Patch ✗ No
Published 2026-02-27
Source Feed nvd
Views 4
🇸🇦 Saudi Risk Score
6.0
/ 10.0 — Saudi Risk
Priority: MEDIUM
🏷️ Tags
CWE-306
Share this CVE

💬 التعليقات

0
جارٍ التحميل
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.