Data Retrieval Vulnerability in Collabora Online by Collabora
CVE-2026-23623
What is CVE-2026-23623?
Collabora Online, a collaborative online office suite, has a vulnerability that allows a user with view-only rights to download shared files without authorization. This occurs when the user initiates a download process via keyboard shortcuts, circumventing established access restrictions. This flaw can lead to unauthorized data retrieval, posing significant risks to the confidentiality of sensitive information shared within the platform. The issue has been addressed in the latest updates, urging users to upgrade to the patched versions for enhanced security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
online Collabora Online < 25.04.7.5 < Collabora Online 25.04.7.5
online Collabora Online < 24.04.17.3 < Collabora Online 24.04.17.3
online Collabora Online < 23.05.20.1 < Collabora Online 23.05.20.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
