CVE-2026-53497CWE-200CWE-359information-disclosure

CVE-2026-53497

Medium · published August 22, 2026

CVSS v3.1
5.3
EPSS
0%
Percentile
14.2
In the wild
Unconfirmed
What it is

CrossWatch (CW) is a synchronization engine. Prior to version 0.9.21, GET /api/app-auth/status is accessible without authentication and returns the other_sessions array, which exposes metadata of all active sessions — including originating IP addresses, User-Agent strings, internal session IDs, and creation/expiry timestamps. Any unauthenticated network attacker can enumerate this data without credentials. Version 0.9.21 fixes the issue.

The record
Technical detail
CVSS v3.1
5.3 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00234 · 14.2th percentile
Weaknesses
CWE-200 · Exposure of Sensitive Information to an Unauthorized Actor; CWE-359 · Exposure of Private Personal Information to an Unauthorized Actor
Published
2026-08-22T02:16Z
References (3)
EPSS history
Timeline
  • 21 AUG 21:19Z
    CrossWatch: Unauthenticated /api/app-auth/status endpoint leaks active session metadata (IP, User-Agent, session IDs)
    cvelistv5