Token Transfer Exposure in Etherpad Collaborative Editor
CVE-2026-55088

6.8MEDIUM

Key Information:

Vendor

Ether

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-55088?

The Etherpad collaborative editor has a security flaw concerning its token transfer mechanism. In versions 2.6.0 to 3.1.0, an author token is generated and stored via the POST /tokenTransfer route without proper expiration checks. This token can be accessed via GET /tokenTransfer/{uuid}, allowing an unauthenticated attacker to exploit it. Once the attacker retrieves the transfer UUID, they can redeem it multiple times, gaining fresh author cookies and reading the raw token data. This vulnerability poses a significant risk, enabling unauthorized actions on collaborative pads by impersonating legitimate users. The issue is resolved in Etherpad version 3.1.0.

Affected Version(s)

etherpad >= 2.6.0, < 3.1.0

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.