PT-2026-35821 · Outline · Outline

·

CVE-2026-41649

·

Published

2026-04-28

·

Updated

2026-05-01

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Outline versions 0.86.0 through 1.6.9
Description An insecure direct object reference exists in the 'shares.create' API endpoint. When both collectionId and documentId are provided in a request, the authorization logic verifies access to the collection but ignores the document. This allows an authenticated attacker to generate a valid public share link for any document on the platform, including those from other workspaces. The full contents of the document can subsequently be retrieved via the 'documents.info' endpoint.
Recommendations Update to version 1.7.0.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41649
GHSA-23JJ-RP48-W7Q7

Affected Products

Outline