Vulnerability in Docmost Wiki Software Allows Unauthorized Access to Restricted Attachments
CVE-2026-48073
4.3MEDIUM
What is CVE-2026-48073?
In Docmost versions 0.70.0 to 0.80.1, a low-privileged authenticated user can exploit the system by embedding a forged attachmentId linked to a restricted page. This vulnerability allows the user to export an attacker-controlled page with the 'includeAttachments=true' parameter. This action compels the export flow to retrieve the restricted attachment from storage, which should otherwise be protected, and includes it in the resulting ZIP archive despite direct access being denied. This flaw is addressed in version 0.80.1.
Affected Version(s)
docmost >= 0.70.0, < 0.80.1
