PT-2026-103275 · Vaadin · Vaadin

·

CVE-2026-93547

·

Published

2026-09-30

·

Updated

2026-09-30

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Vaadin versions 23.1.0 through 23.6.13 Vaadin versions 24.0.0 through 24.9.21 Vaadin versions 24.10.0 through 24.10.9 Vaadin versions 25.0.0 through 25.1.11 Vaadin versions 25.2.0 through 25.2.6 Vaadin Framework 7 and 8 with Spreadsheet add-on versions 2.0.0 through 3.1.0
Description A missing authorization check in the Vaadin Spreadsheet component allows an authenticated user to add or replace cell comments on a sheet with protection enabled, including locked cells. Additionally, writing a comment to a non-existent cell will result in the creation of both the row and the cell.
Recommendations Upgrade Vaadin versions 23.1.0 through 23.6.13 to 23.6.14. Upgrade Vaadin versions 24.0.0 through 24.9.21 to 24.9.22. Upgrade Vaadin versions 24.10.0 through 24.10.9 to 24.10.10. Upgrade Vaadin versions 25.0.0 through 25.1.11 to 25.1.12. Upgrade Vaadin versions 25.2.0 through 25.2.6 to 25.2.7 or newer. Upgrade the Spreadsheet add-on for Vaadin Framework 7 and 8 to 3.1.1.

Fix

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93547

Affected Products

Vaadin