Aller au contenu

Fiche vulnérabilité

CVE-2026-84204 : vulnérabilité moyenne (CVSS 6.5)

Description

GROWI contains an access control vulnerability in the GET /_api/v3/attachment/:id endpoint that fails to validate page access permissions. Authenticated attackers can retrieve attachment metadata from pages they cannot view by supplying known attachment identifiers.

En bref

Sévérité
Moyenne (CVSS 6.5)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitation active
Non signalée par la CISA
Publication
1 sept. 2026
Dernière mise à jour
8 sept. 2026

Références

Rechercher une autre vulnérabilité dans la base CVE