CVE-2026-53620
MEDIUM
NVD
CVSS Score
6.3
Severity
MEDIUM
Published
Aug 31, 2026
Vendor
unknown
Description
GROWI contains a vulnerability with an authorization bypass through user-controlled key in the bookmark folder APIs. If this vulnerability is exploited, an authenticated attacker could retrieve, tamper with, and/or delete the other user's bookmark data.