CVE-2026-39957 | Lychee up to 7.5.3 listAll authorization (GHSA-4v4c-g2jv-4g25)
A vulnerability, which was classified as problematic, was found in Lychee up to 7.5.3. This issue affects the function SharingController::listAll. Such manipulation leads to incorrect authorization.
This vulnerability is traded as CVE-2026-39957. The attack may be launched remotely. There is no exploit available.
You should upgrade the affected component.