Logic Flaw in Outline API Affects Collaborative Documentation Services
CVE-2026-28506

4.3MEDIUM

Key Information:

Vendor

Outline

Status
Vendor
CVE Published:
17 March 2026

What is CVE-2026-28506?

The Outline service, used for collaborative documentation, is affected by a logic flaw in the events.list API endpoint prior to version 1.5.0. This flaw allows any authenticated user to access activity logs linked to documents lacking a collection, including private drafts and deleted documents, irrespective of their actual permissions. While the content of these documents remains secure, crucial metadata such as Document IDs, user activity timestamps, and in some instances, Document Titles of Permanently Deleted documents are exposed. This exposure compromises the randomness of UUID protection, facilitating high-severity IDOR attacks that could be easily executed with reduced complexity. The issue has been addressed in version 1.5.0.

Affected Version(s)

outline < 1.5.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.