MEDIUM
YaoApp
CVE published 2026-09-15
CVE-2026-91774
CVE-2026-91774 is a medium-severity vulnerability in the Yao application, where an authenticated but unauthorized user can read full team records by supplying a known team identifier to the GET /user/teams/:id endpoint. This vulnerability allows attackers to access sensitive team data, including names, descriptions, owner information, and settings, without proper authorization or membership verification. [truncated]