PT-2026-84303 · Growi · Growi

·

CVE-2026-84205

·

Published

2026-09-01

·

Updated

2026-09-01

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions GROWI versions prior to 8.0.2
Description An access control issue exists in the GET '/ api/v3/revisions/:id' endpoint. The system validates access based on a query parameter but returns the revision specified by the path parameter :id without verifying that both refer to the same page. This allows authenticated attackers to use a page identifier they are authorized to access alongside an arbitrary revision identifier to read content from pages for which they lack permission.
Recommendations Update GROWI to version 8.0.2 or later.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84205

Affected Products

Growi