Privilege Escalation in Docmost Open-Source Collaborative Wiki Software
CVE-2026-52853

5.2MEDIUM

Key Information:

Vendor

Docmost

Status
Vendor
CVE Published:
24 September 2026

What is CVE-2026-52853?

Docmost, an open-source collaborative wiki and documentation software, has a security issue where an authenticated workspace ADMIN can invite external users with OWNER-level permissions. This is due to a flaw in the role ceiling management that fails to restrict ADMIN users from granting elevated privileges. When the invited user accepts the invitation, they gain the capability to perform actions reserved for the highest privilege level, including creating backdoor accounts or empowering colluding external users. This vulnerability has been addressed in version 0.90.1.

Affected Version(s)

docmost < 0.90.1

References

CVSS V3.1

Score:
5.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.