Privilege Escalation in Docmost Open-Source Collaborative Wiki Software
CVE-2026-52853
5.2MEDIUM
What is CVE-2026-52853?
Docmost, an open-source collaborative wiki and documentation software, has a security issue where an authenticated workspace ADMIN can invite external users with OWNER-level permissions. This is due to a flaw in the role ceiling management that fails to restrict ADMIN users from granting elevated privileges. When the invited user accepts the invitation, they gain the capability to perform actions reserved for the highest privilege level, including creating backdoor accounts or empowering colluding external users. This vulnerability has been addressed in version 0.90.1.
Affected Version(s)
docmost < 0.90.1
