PT-2026-98240 · Docmost · Docmost

CVE-2026-52853

·

Published

2026-09-24

·

Updated

2026-09-24

CVSS v3.1

5.2

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Docmost versions prior to 0.90.1
Description An authenticated workspace ADMIN can exploit the workspace invitation flow to invite an external email address and assign it the OWNER role. This occurs because the role ceiling does not prevent ADMIN users from granting privileges that exceed their own. Once the invitation is accepted, the new account is granted OWNER-level permissions, which can be used to create a backdoor OWNER account or promote a colluding external user to the highest privilege level within the workspace.
Recommendations Update to version 0.90.1.

Exploit

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-52853
GHSA-84FX-MVQX-P5GX

Affected Products

Docmost