Authorization Flaw in Etherpad Allows Non-Admin Users to Perform Admin Functions
CVE-2026-55089
9.9CRITICAL
What is CVE-2026-55089?
Etherpad, a real-time collaborative editing tool, has a significant vulnerability affecting versions 2.1.0 to 3.0.0. The issue arises from improper authorization checks in the OAuth implementation, specifically concerning the admin claim in the API requests. Non-admin users with valid signed tokens can exploit this flaw to execute sensitive administrative actions such as modifying, deleting, or disclosing pads across the instance. This includes functionality that can compromise the integrity and security of collaborative documents. The vulnerability is addressed in version 3.1.0, making an upgrade essential for all users.
Affected Version(s)
etherpad >= 2.1.0, < 3.1.0
