PT-2026-76574 · Etherpad · Etherpad

CVE-2026-55088

·

Published

2026-08-13

·

Updated

2026-08-21

CVSS v3.1

6.8

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Etherpad versions 2.6.0 through 3.0.0
Description An issue exists in the device-to-device author-token transfer mechanism. The system uses the POST /tokenTransfer endpoint to store an author token and exposes it via the GET /tokenTransfer/{uuid} endpoint. This implementation contains three flaws: it lacks an expiration check for the transfer record, fails to remove the record after it has been redeemed, and returns the raw author token in the response body of the GET request. An unauthenticated attacker who obtains a transfer uuid can repeatedly redeem it to receive fresh author cookies and read the cleartext token, allowing them to impersonate the originating author for read and write operations.
Recommendations Update to version 3.1.0. As a temporary mitigation, reverse-proxy block the /tokenTransfer/* endpoint if device-pairing is not in use. As a temporary mitigation, disable any UI that surfaces the transfer URL, such as QR codes or copy buttons.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55088
GHSA-VQFP-P66C-XRP9

Affected Products

Etherpad