CORS Misconfiguration in CollabPlatform Affects User Data Security
CVE-2026-27579

7.4HIGH

Key Information:

Vendor

Karnop

Vendor
CVE Published:
21 February 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-27579?

CollabPlatform, a comprehensive real-time document collaboration tool, suffers from a serious vulnerability due to improper CORS configuration. This misconfiguration allows requests from arbitrary origins while accepting credentialed requests, enabling attackers to execute cross-origin requests from a domain they control. As a result, they can access sensitive user data, including email addresses, account identifiers, and multi-factor authentication statuses. Currently, there is no fix available for this vulnerability, posing a significant risk to user privacy and security.

Affected Version(s)

realtime-collaboration-platform <= master

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.