CVE-2026-101004 Details
Description
A security vulnerability has been detected in notionnext-org NotionNext up to 4.10.10. Affected by this issue is the function cleanCache of the file pages/api/cache.js of the component Authentication Guard. The manipulation of the argument token leads to missing authentication. The attack may be initiated remotely. Versions 4.1.0 - 4.9.5.2 allow unauthenticated exploitation due to missing method check. In versions 4.9.5.7 - 4.10.10 a guard present but only enforced when CACHE_REVALIDATION_TOKEN is set. Default deployments remain unprotected. The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability allowing missing authentication has been identified in NotionNext versions through 4.10.10. The issue arises in the Authentication Guard component, specifically within the cleanCache function of pages/api/cache.js. The vulnerability can be exploited remotely by manipulating the token argument. In versions 4.1.0 to 4.9.5.2, the absence of a method check allowed for unauthenticated exploitation. Although versions 4.9.5.7 to 4.10.10 include a guard, it is only enforced when CACHE_REVALIDATION_TOKEN is set, leaving default deployments unprotected.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 28, 2026CISA-ADP
Assessed Sep 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://vuldb.com/cve/CVE-2026-101004 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/920379 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/410874 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/410874/cti | [email protected] | Permission Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | [email protected] |
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| notionnext-org NotionNext | >= 4.1.0, <= 4.9.5.2 >= 4.9.5.7, <= 4.10.10 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 28, 2026 | CVE Modified | CISA-ADP |
| Sep 28, 2026 | New CVE Received | [email protected] |
Volerion