PT-2026-84302 · Growi · Growi

·

CVE-2026-84204

·

Published

2026-09-01

·

Updated

2026-09-01

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions GROWI versions prior to 8.0.2
Description An access control issue exists where the system fails to validate page access permissions. Authenticated attackers can retrieve attachment metadata from pages they are not authorized to view by providing known attachment identifiers to the 'GET / api/v3/attachment/:id' endpoint.
Recommendations Update GROWI to version 8.0.2 or later. Restrict access to the 'GET / api/v3/attachment/:id' endpoint to minimize the risk of unauthorized metadata retrieval.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84204

Affected Products

Growi