CVE-2026-101004
Last modified
CVE-2026-101004 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. A security vulnerability has been detected in notionnext-org NotionNext up to 4.10.10. Affected by this issue is the function cleanCache of the file pages/api/cache.js of the component Authentication Guard.
Description
A security vulnerability has been detected in notionnext-org NotionNext up to 4.10.10. Affected by this issue is the function cleanCache of the file pages/api/cache.js of the component Authentication Guard. The manipulation of the argument token leads to missing authentication. The attack may be initiated remotely. Versions 4.1.0 - 4.9.5.2 allow unauthenticated exploitation due to missing method check. In versions 4.9.5.7 - 4.10.10 a guard present but only enforced when CACHE_REVALIDATION_TOKEN is set. Default deployments remain unprotected. The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| notionnext-org | NotionNext | 4.10.0; 4.10.1; 4.10.2; 4.10.3; 4.10.4; 4.10.5; 4.10.6; 4.10.7; 4.10.8; 4.10.9; 4.10.10 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-101004?
How severe is CVE-2026-101004?
How do I fix CVE-2026-101004?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-1010A stored cross-site scripting (XSS) vulnerability exists in …5.4
- CVE-2026-10100The Simple Custom Login Page plugin for WordPress is vulnera…4.4
- CVE-2026-101000A vulnerability was determined in Netcore NBR100V2 1.3.24061…10
- CVE-2026-101001A vulnerability was identified in Netcore NBR200V2 1.3.24112…10
- CVE-2026-101002A security flaw has been discovered in Netcore NBR200V2 1.3.…9.9
- CVE-2026-101003A weakness has been identified in Cesanta Mongoose up to 7.2…5.3
- CVE-2026-101005A vulnerability was detected in October CMS up to 4.3.4. Thi…7.3
- CVE-2026-101006A flaw has been found in Frappe HR up to 16.15.0. This vulne…4.3
- CVE-2026-101007A vulnerability has been found in aaPanel BaoTa up to 11.8.0…8.4
- CVE-2026-101008A vulnerability was found in aaPanel BaoTa up to 11.8.0. Imp…9.1
- CVE-2026-101009A vulnerability was determined in aaPanel BaoTa up to 11.8.0…8.4
- CVE-2026-10101ACM/MCE assisted-service writes raw referenced pull-secret c…6.3
Are you affected by CVE-2026-101004?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
