PT-2026-94074 · Docs · Docs
CVSS v4.0
7.6
High
| Vector | AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Docs versions prior to 5.4.1
Description
An issue exists where websocket collaboration connections are not properly revoked when access is removed at the parent document level. This allows users whose access has been revoked to maintain real-time read and write access to sub-documents via open websocket sessions that remain active.
Recommendations
Update to version 5.4.1 or later.
Exploit
Fix
Insufficient Session Expiration
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Docs