CVE-2026-35023 Details
Description
Wimi Teamwork On-Premises versions prior to 8.2.0 contain an insecure direct object reference vulnerability in the preview.php endpoint where the item_id parameter lacks proper authorization checks. Attackers can enumerate sequential item_id values to access and retrieve image previews from other users' private or group conversations, resulting in unauthorized disclosure of sensitive information.
A vulnerability allowing insecure direct object reference has been identified in Wimi Teamwork On-Premises versions prior to 8.2.0. This vulnerability exists in the preview.php endpoint, where the item_id parameter is not properly authorized. As a result, attackers can sequentially enumerate item_id values to access and retrieve image previews from private or group conversations of other users, leading to unauthorized disclosure of sensitive information.
Users can update to Wimi Teamwork On-Premises version 8.2.0 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.vulncheck.com/advisories/wimi-teamwork-on-premises-idor-via-preview-php | [email protected] | Third Party Advisory |
| https://www.wimi-teamwork.com/en/product-update | [email protected] | Release Notes |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| wimi-teamwork wimi-teamwork | < 8.2.0 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 2, 2026 | Initial Analysis | [email protected] |
| Apr 9, 2026 | CVE Modified | [email protected] |
| Apr 8, 2026 | New CVE Received | [email protected] |