PT-2026-94074 · Docs · Docs

·

CVE-2026-92800

·

Published

2026-09-16

·

Updated

2026-09-19

CVSS v4.0

7.6

High

VectorAV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Docs versions prior to 5.4.1
Description An issue exists where websocket collaboration connections are not properly revoked when access is removed at the parent document level. This allows users whose access has been revoked to maintain real-time read and write access to sub-documents via open websocket sessions that remain active.
Recommendations Update to version 5.4.1 or later.

Exploit

Fix

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92800

Affected Products

Docs