PT-2026-97860 · Unknown · Lasuite Doc
CVE-2026-76907
·
Published
2026-09-24
·
Updated
2026-09-24
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
LaSuite Doc versions 4.8.2 through 5.3.x
Description
An issue exists in the collaborative note taking, wiki, and documentation platform where the endpoint "/api/v1.0/documents/search/" accepts sequential seven-digit document paths to scope descendant searches without requiring the public document UUID. An unauthenticated caller can submit an empty search query and iterate predictable path values to enumerate public document subtrees, exposing document identifiers, titles, creator data, timestamps, and tree metadata. These identifiers can then be used via public-document endpoints to retrieve content. Additionally, the difference between 403 Forbidden and 404 Not Found responses allows an attacker to verify if a guessed path exists. Authenticated users can similarly discover documents within their authenticated link reach, although restricted documents remain protected.
Recommendations
Update to version 5.4.0.
Exploit
Fix
IDOR
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Lasuite Doc