Unknown · Notionnext · CVE-2026-101004
**Name of the Vulnerable Software and Affected Versions**
NotionNext versions 4.1.0 through 4.10.10
**Description**
An issue exists in the Authentication Guard component within the `cleanCache()` function of the `pages/api/cache.js` file. Remote manipulation of the `token` argument can lead to a complete bypass of authentication. In versions 4.1.0 through 4.9.5.2, the flaw is caused by a missing method check. In versions 4.9.5.7 through 4.10.10, a guard is present but is only enforced if the `CACHE REVALIDATION TOKEN` variable is configured, leaving default deployments unprotected.
**Recommendations**
For versions 4.1.0 through 4.10.10, set the `CACHE REVALIDATION TOKEN` variable to ensure the authentication guard is enforced.
As a temporary mitigation, restrict access to the `pages/api/cache.js` endpoint.