CVE-2026-85697 Details
Description
Documenso 2.17.0 contains an access control vulnerability in the PDF-serving endpoint that fails to validate document visibility settings. Attackers with low privileges can read restricted documents within their team or cross-tenant by leveraging missing ownership validation on document data identifiers.
A vulnerability in Documenso version 2.17.0 allows low-privilege users to access restricted documents through the PDF-serving endpoint. The issue arises because the endpoint does not properly validate document visibility settings, enabling unauthorized access to documents within the same team or across different tenants. This flaw exploits the absence of ownership verification for document data identifiers, potentially leading to the disclosure of confidential signed documents.
The vulnerability can be addressed by modifying the access control checks in the PDF-serving endpoint to include proper validation of document visibility settings. Additionally, ownership verification should be implemented for document data identifiers to prevent cross-tenant access.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 4, 2026CISA-ADP
Assessed Sep 4, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/documenso/documenso/issues/3112 | CISA-ADP | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/documenso/documenso | [email protected] | Vendor |
| https://github.com/documenso/documenso/blob/v2.17.0/apps/remix/server/api/files/files.helpers.ts | [email protected] | Source CodeVendor |
| https://github.com/documenso/documenso/issues/3112 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://www.vulncheck.com/advisories/documenso-2.17.0-pdf-route-ignores-document-visibility | [email protected] | Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Documenso | <= 2.17.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 4, 2026 | CVE Modified | CISA-ADP |
| Sep 4, 2026 | New CVE Received | [email protected] |
Volerion