Access Control Vulnerability in GROWI by GROWI Labs
CVE-2026-84205
7.1HIGH
What is CVE-2026-84205?
GROWI exemplifies a critical access control vulnerability at the GET /_api/v3/revisions/:id endpoint. The issue arises when the access validation method relies solely on a query parameter, permitting authenticated attackers to exploit mismatched identifiers. By pairing an accessible page identifier with an arbitrary revision identifier, these attackers can retrieve revision content from pages where they lack appropriate permissions, ultimately leading to significant unauthorized data exposure.
Affected Version(s)
growi 0 <= 8.0.2
