Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 01 Sep 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GROWI contains an access control vulnerability in the GET /_api/v3/attachment/:id endpoint that fails to validate page access permissions. Authenticated attackers can retrieve attachment metadata from pages they cannot view by supplying known attachment identifiers. | |
| Title | GROWI through 8.0.2 Missing Authorization on apiv3 Attachment Retrieval | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-01T15:51:25.209Z
Reserved: 2026-09-01T11:03:27.973Z
Link: CVE-2026-84204
Updated: 2026-09-01T15:51:21.324Z
Status : Received
Published: 2026-09-01T16:17:34.747
Modified: 2026-09-01T16:17:34.747
Link: CVE-2026-84204
No data.
OpenCVE Enrichment
Updated: 2026-09-02T03:15:04Z