THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-9284-fjc3-fmmj (medium) — Sakai Profile Image Deletion has an IDOR

[GHSA] GHSA-9284-fjc3-fmmj (medium) — Sakai Profile Image Deletion has an IDOR

highgithub_advisoriesPublished 2026-08-24

GHSA-9284-fjc3-fmmj Severity: medium CVE: CVE-2026-54050

Sakai Profile Image Deletion has an IDOR

### Summary

The Sakai REST API endpoint `DELETE /api/users/{userId}/profile/image` does not verify that the requesting user is authorized to modify the target user's profile. Any authenticated user can delete the profile image of any other user, including administrators, by supplying a different `u

Indicators of compromise

Original source: https://github.com/advisories/GHSA-9284-fjc3-fmmj