CVE-2026-52850
Last modified
CVE-2026-52850 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. Docmost is open-source collaborative wiki and documentation software. Prior to 0.90.1, an authenticated workspace member who does not belong to a private space can call the transclusion / sync-block lookup API with a known sourcePageId and transclusionId pair because the lookup does not enforce private space membership before resolving the source page.
Description
Docmost is open-source collaborative wiki and documentation software. Prior to 0.90.1, an authenticated workspace member who does not belong to a private space can call the transclusion / sync-block lookup API with a known sourcePageId and transclusionId pair because the lookup does not enforce private space membership before resolving the source page. The API can return confidential sync-block content and source page metadata even though the normal page APIs deny access to the same page. This issue is fixed in version 0.90.1.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-52850?
How severe is CVE-2026-52850?
How do I fix CVE-2026-52850?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-52842Lightpanda is a headless browser designed for AI and automat…9.3
- CVE-2026-52843Lightpanda is a headless browser designed for AI and automat…9.3
- CVE-2026-52844Caddy is an extensible server platform that uses TLS by defa…7.5
- CVE-2026-52845Caddy is an extensible server platform that uses TLS by defa…8.1
- CVE-2026-52846Caddy is an extensible server platform that uses TLS by defa…4.2
- CVE-2026-5285Use after free in WebGL in Google Chrome prior to 146.0.7680…8.8
- CVE-2026-52851Traccar is an open source GPS tracking system. Prior to 6.14…7.1
- CVE-2026-52852Traccar is an open source GPS tracking system. Prior to 6.14…6.5
- CVE-2026-52853Docmost is open-source collaborative wiki and documentation …5.2
- CVE-2026-52854Maps is a MediaWiki extension that enables visualization of …8.6
- CVE-2026-52855Wings is the server control plane for Pterodactyl, a free, o…9.9
- CVE-2026-52856Wings is the server control plane for Pterodactyl, a free, o…7.5
Are you affected by CVE-2026-52850?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
