Improper Authorization Vulnerability in Docmost Wiki Software
CVE-2026-34213
5.4MEDIUM
What is CVE-2026-34213?
Docmost, an open-source collaborative wiki and documentation software, is susceptible to an improper authorization issue. This vulnerability allows a low-privileged authenticated user to overwrite another user's attachment by submitting the victim's attachmentId through a specific API endpoint. This issue arises in versions from 0.3.0 up to, but not including, 0.71.0. Importantly, the attack can be executed remotely without interaction from the targeted user, posing a significant integrity risk within shared workspaces. The vulnerability has been addressed and patched in version 0.71.0.
Affected Version(s)
docmost >= 0.3.0, < 0.71.0
