PT-2026-99769 · Unknown · Notionnext

·

CVE-2026-101004

·

Published

2026-09-28

·

Updated

2026-09-28

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions NotionNext versions 4.1.0 through 4.10.10
Description An issue exists in the Authentication Guard component within the cleanCache() function of the pages/api/cache.js file. Remote manipulation of the token argument can lead to a complete bypass of authentication. In versions 4.1.0 through 4.9.5.2, the flaw is caused by a missing method check. In versions 4.9.5.7 through 4.10.10, a guard is present but is only enforced if the CACHE REVALIDATION TOKEN variable is configured, leaving default deployments unprotected.
Recommendations For versions 4.1.0 through 4.10.10, set the CACHE REVALIDATION TOKEN variable to ensure the authentication guard is enforced. As a temporary mitigation, restrict access to the pages/api/cache.js endpoint.

Fix

Improper Authentication

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-101004

Affected Products

Notionnext