Medium severity4.3NVD Advisory· Published Apr 19, 2022· Updated Jul 9, 2026
CVE-2022-26595
CVE-2022-26595
Description
Liferay Portal 7.3.7, 7.4.0, and 7.4.1, and Liferay DXP 7.2 fix pack 13, and 7.3 fix pack 2 does not properly check user permission when accessing a list of sites/groups, which allows remote authenticated users to view sites/groups via the user's site membership assignment UI.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.liferay.portal:release.portal.bomMaven | >= 7.4.0, < 7.4.2-ga3 | 7.4.2-ga3 |
com.liferay.portal:release.dxp.bomMaven | >= 7.2.0, < 7.2.10.fp13 | 7.2.10.fp13 |
com.liferay.portal:release.dxp.bomMaven | >= 7.3.0, < 7.3.10.fp2 | 7.3.10.fp2 |
com.liferay:com.liferay.site.browser.webMaven | < 6.0.5 | 6.0.5 |
com.liferay.portal:com.liferay.portal.implMaven | < 7.7.9 | 7.7.9 |
Affected products
11cpe:2.3:a:liferay:digital_experience_platform:7.2:fix_pack_13:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:liferay:digital_experience_platform:7.2:fix_pack_13:*:*:*:*:*:*
- cpe:2.3:a:liferay:digital_experience_platform:7.3:fix_pack_2:*:*:*:*:*:*
- osv-coords5 versionspkg:bitnami/liferaypkg:maven/com.liferay.portal/com.liferay.portal.implpkg:maven/com.liferay.portal/release.dxp.bompkg:maven/com.liferay.portal/release.portal.bompkg:maven/com.liferay/com.liferay.site.browser.web
>= 7.2-fix.0, <= 7.2-fix.0+ 4 more
- (no CPE)range: >= 7.2-fix.0, <= 7.2-fix.0
- (no CPE)range: < 7.7.9
- (no CPE)range: >= 7.2.0, < 7.2.10.fp13
- (no CPE)
- (no CPE)range: < 6.0.5
Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-822f-jfpg-hg7hghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-26595ghsaADVISORY
- portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2022-26595-unauthorized-access-to-site-group-listnvdVendor Advisory
- github.com/liferay/liferay-portal/commit/5b958de42d93f1ba5879a0a20054b14ad7f145c4ghsaWEB
- liferay.atlassian.net/issues/LPE-17367ghsaWEB
- liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2022-26595-unauthorized-access-to-site-group-listghsaWEB
News mentions
0No linked articles in our index yet.