CVE-2026-48073 Details
Description
Docmost is open-source collaborative wiki and documentation software. From 0.70.0 until 0.80.1, a low-privileged authenticated user who can edit an exportable page can embed a forged attachmentId that belongs to a restricted page in the same space. Exporting the attacker-controlled page with includeAttachments=true causes the page export flow to read the restricted attachment from storage and include it in the returned ZIP archive even though direct file download denies access. This issue is fixed in version 0.80.1.
A vulnerability in Docmost versions 0.70.0 prior to 0.80.1 allows low-privileged authenticated users to export restricted attachments from the same space by embedding a forged attachment ID into an exportable page. While direct downloads of the restricted attachments are denied, the export feature can be manipulated to include these attachments in the exported ZIP archive. This issue has been addressed in version 0.80.1.
Users can upgrade to Docmost version 0.80.1 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 24, 2026CISA-ADP
Assessed Sep 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/docmost/docmost/commit/a573acedd0317f3472cb0f8b95f6aa15315312e5 | [email protected] | Source CodeVendor |
| https://github.com/docmost/docmost/releases/tag/v0.80.1 | [email protected] | Release NotesVendor |
| https://github.com/docmost/docmost/security/advisories/GHSA-rxm9-xp9h-4c84 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Docmost | >= 0.70.0, <= 0.80.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 24, 2026 | CVE Modified | CISA-ADP |
| Sep 24, 2026 | New CVE Received | [email protected] |
Volerion