Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-84204

MEDIUM NVD
CVSS Score 6.5
Severity MEDIUM
Published Sep 01, 2026
Vendor unknown

Description

GROWI contains an access control vulnerability in the GET /_api/v3/attachment/:id endpoint that fails to validate page access permissions. Authenticated attackers can retrieve attachment metadata from pages they cannot view by supplying known attachment identifiers.

References