CVE-2026-52853

MEDIUM Status: Deferred

CVSS Scores

CVSS v3.x Base Score
5.2
MEDIUM

Description

Docmost is open-source collaborative wiki and documentation software. Prior to 0.90.1, an authenticated workspace ADMIN can use the workspace invitation flow to invite an external email address with the OWNER role because the role ceiling does not prevent ADMIN users from granting privileges above their own. When the invitation is accepted, the new account receives OWNER-level permissions, allowing the ADMIN to create a backdoor OWNER account or promote a colluding external user to the workspace's highest privilege level. This issue is fixed in version 0.90.1.

Published
September 24, 2026 7:17 PM
Last Modified
September 24, 2026 7:17 PM
Source
[email protected]

Weaknesses (CWE)

CWE-269

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.