Improper Authorization Flaw in Documize Community's Attachment Download Functionality
CVE-2026-71234
7.5HIGH
What is CVE-2026-71234?
The Documize Community platform exhibits an improper authorization vulnerability within its attachment download functionality. Specifically, the attachment download endpoint accepts a 'secure' query parameter that, if provided with any non-empty value, allows bypassing authentication. This flaw permits unauthorized users to access and download sensitive attachments from various organizations, emphasizing a significant security oversight. Other related handlers in the same code file enforce proper session-based authorization, indicating that this lack of authentication checks is an inconsistency that must be rectified to safeguard user data.
Affected Version(s)
community 0
