Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-55089

Опубликовано: 19 авг. 2026
Источник: nvd
CVSS3: 9.9
EPSS Низкий

Описание

Etherpad is a real-time collaborative editor. From 2.1.0 until 3.1.0, Etherpad's src/node/handler/APIHandler.ts authorizes requests to /api/2/* in the authorization_code OAuth path by using requiredClaims with the admin claim. This check requires only that the claim exists, while src/node/security/OAuth2Provider.ts issues admin: false for configured non-admin users. A non-admin user with a valid signed token can therefore invoke administrative functions including setHTML, setText, appendText, deletePad, copyPad, movePad, restoreRevision, anonymizeAuthor, listAllPads, and listAuthorsOfPad, allowing disclosure, modification, or deletion of pads across the instance. This issue is fixed in version 3.1.0.

EPSS

Процентиль: 38%
0.00443
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 9.9
debian
около 1 месяца назад

Etherpad is a real-time collaborative editor. From 2.1.0 until 3.1.0, ...

EPSS

Процентиль: 38%
0.00443
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-863