CVE-2026-84204 - GROWI through 8.0.2 Missing Authorization on apiv3 Attachment Retrieval
CVE ID :CVE-2026-84204
Published : Sept. 1, 2026, 4:17 p.m. | 14 minutes ago
Description :GROWI contains an access control vulnerability in the GET /_api/v3/attachment/:id endpoint that fails to validate page access permissions. Authenticated attackers can retrieve attachment metadata from pages they cannot view by supplying known attachment identifiers.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Sept. 1, 2026, 4:17 p.m. | 14 minutes ago
Description :GROWI contains an access control vulnerability in the GET /_api/v3/attachment/:id endpoint that fails to validate page access permissions. Authenticated attackers can retrieve attachment metadata from pages they cannot view by supplying known attachment identifiers.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...