Missing Authorization Check in Vaadin Spreadsheet Component
CVE-2026-93547

5.3MEDIUM

Key Information:

Vendor

Vaadin

Vendor
CVE Published:
30 September 2026

What is CVE-2026-93547?

The Vaadin Spreadsheet component has a security issue due to a missing authorization check that allows authenticated users to manipulate cell comments on protected sheets. This vulnerability enables users to add or replace comments on locked cells, potentially compromising data integrity by allowing unauthorized modifications—such actions create new rows and cells in the spreadsheet. Affected users are advised to upgrade to the specified versions to mitigate this risk and ensure the application remains secure.

Affected Version(s)

vaadin 23.1.0 < 23.6.14

vaadin 24.0.0 < 24.9.22

vaadin 24.10.0 < 24.10.10

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Arpit Jain
.