CVE Vulnerabilities

CVE-2026-29788

Unverified Ownership

Published: Mar 06, 2026 | Modified: Mar 11, 2026
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

TSPortal is the WikiTide Foundation’s in-house platform used by the Trust and Safety team to manage reports, investigations, appeals, and transparency work. Prior to version 30, conversion of empty strings to null allows disguising DPA reports as genuine self-deletion reports. This issue has been patched in version 30.

Weakness

The product does not properly verify that a critical resource is owned by the proper entity.

Affected Software

NameVendorStart VersionEnd Version
TsportalWikitide*30 (excluding)

Potential Mitigations

References