CVE-2026-85697
Documenso 2.17.0 contains an access control vulnerability in the PDF-serving endpoint that fails to validate document visibility settings. Attackers with low privileges can read restricted documents within their team or cross-tenant by leveraging missing ownership validation on document data identifiers.
वीकनेस
Documenso 2.17.0 contains an access control vulnerability in the PDF-serving endpoint that fails to validate document visibility settings. Attackers with low privileges can read restricted documents within their team or cross-tenant by leveraging missing ownership validation on document data identifiers.
संदर्भ
- https://github.com/documenso/documenso
- https://github.com/documenso/documenso/blob/v2.17.0/apps/remix/server/api/files/files.helpers.ts
- https://github.com/documenso/documenso/issues/3112
- https://www.vulncheck.com/advisories/documenso-2.17.0-pdf-route-ignores-document-visibility
- https://github.com/documenso/documenso/issues/3112
हमलावर से पहले बग आप ढूँढें।
GitHub से साइन इन करें और एक मिनट से भी कम में अपना पहला ऑडिट चलाएँ। फ़्री प्लान के लिए क्रेडिट कार्ड की ज़रूरत नहीं।