Improper Authorization Flaw in Documize Community's Attachment Download Functionality
CVE-2026-71234

7.5HIGH

Key Information:

Vendor

Documize

Status
Vendor
CVE Published:
5 August 2026

What is CVE-2026-71234?

The Documize Community platform exhibits an improper authorization vulnerability within its attachment download functionality. Specifically, the attachment download endpoint accepts a 'secure' query parameter that, if provided with any non-empty value, allows bypassing authentication. This flaw permits unauthorized users to access and download sensitive attachments from various organizations, emphasizing a significant security oversight. Other related handlers in the same code file enforce proper session-based authorization, indicating that this lack of authentication checks is an inconsistency that must be rectified to safeguard user data.

Affected Version(s)

community 0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alijonov Alisher
.