Authorization Bypass Vulnerability in AFFiNE by toeverything
CVE-2026-7702
Key Information:
- Vendor
Toeverything
- Status
- Vendor
- CVE Published:
- 3 May 2026
Badges
What is CVE-2026-7702?
A vulnerability has been identified in toeverything AFFiNE versions up to 0.26.3, specifically within the 'allowDocPreview' function of the Public Markdown Preview Endpoint. This flaw enables an unauthorized actor to bypass authorization controls, potentially exposing sensitive documents to unauthorized access. The issue allows for remote exploitation, increasing the severity of the risk. Notably, the vendor was contacted prior to this public disclosure but has not provided a response or remediation.
Affected Version(s)
AFFiNE 0.26.0
AFFiNE 0.26.1
AFFiNE 0.26.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
