5.4
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Description
CVE-2026-34213 A low-privileged Docmost user could supply a victim attachmentId to the generic upload endpoint and overwrite another page's stored attachment inside the same workspace. Intro I identified, responsibly disclosed, and reproduced a...
Basic Information
ID
0A738D4C-E642-58D3-988B-4E964946EC66
Published
Jun 26, 2026 at 12:43
Modified
Jun 26, 2026 at 12:44