Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 01 Sep 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GROWI contains an access control vulnerability in the GET /_api/v3/attachment/:id endpoint that fails to validate page access permissions. Authenticated attackers can retrieve attachment metadata from pages they cannot view by supplying known attachment identifiers. | |
| Title | GROWI through 8.0.2 Missing Authorization on apiv3 Attachment Retrieval | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-01T15:51:25.209Z
Reserved: 2026-09-01T11:03:27.973Z
Link: CVE-2026-84204
Updated: 2026-09-01T15:51:21.324Z
Status : Received
Published: 2026-09-01T16:17:34.747
Modified: 2026-09-01T16:17:34.747
Link: CVE-2026-84204
No data.
OpenCVE Enrichment
No data.