Logic Flaw in Outline API Affects Collaborative Documentation Services
CVE-2026-28506
What is CVE-2026-28506?
The Outline service, used for collaborative documentation, is affected by a logic flaw in the events.list API endpoint prior to version 1.5.0. This flaw allows any authenticated user to access activity logs linked to documents lacking a collection, including private drafts and deleted documents, irrespective of their actual permissions. While the content of these documents remains secure, crucial metadata such as Document IDs, user activity timestamps, and in some instances, Document Titles of Permanently Deleted documents are exposed. This exposure compromises the randomness of UUID protection, facilitating high-severity IDOR attacks that could be easily executed with reduced complexity. The issue has been addressed in version 1.5.0.
Affected Version(s)
outline < 1.5.0
