Authentication Guard Vulnerability in NotionNext by notionnext-org
CVE-2026-101004
6.9MEDIUM
What is CVE-2026-101004?
A vulnerability has been identified in NotionNext that allows for unauthenticated exploitation due to a flaw in the Authentication Guard component. Specifically, the cleanCache function located in pages/api/cache.js mishandles the token argument, resulting in a lack of proper authentication checks. In earlier versions, such as 4.1.0 to 4.9.5.2, the absence of a critical method check enables unauthorized access. Although versions 4.9.5.7 to 4.10.10 include a security guard, it is only effective if a specific CACHE_REVALIDATION_TOKEN is set, leaving default deployments open to exploitation. Despite notifications of this security issue, the vendor has not responded.
Affected Version(s)
NotionNext 4.10.0
NotionNext 4.10.1
NotionNext 4.10.2
