A vulnerability was found in Mastodon up to 4.6.3. It has been classified as problematic. Impacted is the function show of the file app/controllers/admin/collections_controller.rb of the component Collections. This manipulation causes information disclosure.

This vulnerability is handled as CVE-2026-72915. The attack can be initiated remotely. There is not any exploit available.

Upgrading the affected component is recommended.