CVE-2024-7266: Nask Ezd Rp

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Incorrect User Management vulnerability in Naukowa i Akademicka Sieć Komputerowa - Państwowy Instytut Badawczy EZD RP allows logged-in user to list all users in the system, including those from other organizations. This issue affects EZD RP: from 15 before 15.84, from 16 before 16.15, from 17 before 17.2.

Affected products

  • Nask Ezd Rp: from 15, before 15.84 (fixed in 15.84); from 16, before 16.15 (fixed in 16.15); from 17, before 17.2 (fixed in 17.2)

Published 2024-08-07. Last modified 2026-06-17.