CVE-2026-88817

An authenticated, non-guest user of Curiosity Workspace could enroll themselves as an administrator and member of an existing access group without an invitation or approval. It did not grant application-wide administrator privileges, and the vulnerability could not be used to obtain root access to the application or its underlying host.
CVSS

No CVSS.

Configurations

No configuration.

History

16 Sep 2026, 13:18

Type Values Removed Values Added
New CVE

Information

Published : 2026-09-16 13:18

Updated : 2026-09-16 14:17


NVD link : CVE-2026-88817

Mitre link : CVE-2026-88817

CVE.ORG link : CVE-2026-88817


JSON object : View

Products Affected

No product.

CWE
CWE-269

Improper Privilege Management

CWE-284

Improper Access Control