VDB
Sign up
—0.0

PYSEC-2026-1459

Indico Insecure Access

Quick fix

PYSEC-2026-1459 — indico: upgrade to the fixed version with the command below.

pip install --upgrade 'indico>=3.3.3'

Details

A Broken Object Level Authorization (BOLA) vulnerability in Indico v3.2.9 allows attackers to access sensitive information via sending a crafted POST request to the component /api/principals.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/indico
Introduced in: 3.2.9Fixed in: 3.3.3
Fixpip install --upgrade 'indico>=3.3.3'

References