A separate NodeBB federation vulnerability, CVE-2026-58593, filed on July 1, 2026, allows an outside server to post and send messages in the name of any local account, including the administrator's. It requires federation to be enabled. No fixed version has been named.