Back

MEDIUM

Docmost: Broken access control in transclusion lookup API leaks sync-block content across private spaces

Published Sep 24, 2026

Description

Docmost is open-source collaborative wiki and documentation software. Prior to 0.90.1, an authenticated workspace member who does not belong to a private space can call the transclusion / sync-block lookup API with a known sourcePageId and transclusionId pair because the lookup does not enforce private space membership before resolving the source page. The API can return confidential sync-block content and source page metadata even though the normal page APIs deny access to the same page. This issue is fixed in version 0.90.1.

Affected products

Remediation

No remediation recorded yet.

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Sep 24, 2026
Updated Sep 29, 2026
Reserved Jun 8, 2026
CISA Vulnrichment
Updated Sep 29, 2026
NVD
Status Deferred
Modified Sep 24, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner GitHub_M
Published Sep 24, 2026
Updated Sep 29, 2026
Exploited since n/a
EUVD-2026-86387