GROWI contains an access control vulnerability in the GET /_api/v3/attachment/:id endpoint that fails to validate page access permissions. Authenticated attackers can retrieve attachment metadata from pages they cannot view by supplying known attachment identifiers.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-01 16:17
Updated : 2026-09-08 20:18
NVD link : CVE-2026-84204
Mitre link : CVE-2026-84204
CVE.ORG link : CVE-2026-84204
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
