CVE-2026-84205 HIGH

CVE-2026-84205: GROWI through 8.0.2 Authorization Bypass Through User-Controlled Key on apiv3 Revision Retrieval

Vendor Growilabs
Product growi
Weakness CWE-639 · IDOR
Published September 1, 2026
Last update September 1, 2026

CVSS base score

7.1/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

GROWI contains an access control vulnerability in the GET /_api/v3/revisions/:id endpoint that validates access against a query parameter but returns the revision identified by the path parameter without confirming they reference the same page. Authenticated attackers can pair a page identifier they can access with an arbitrary revision identifier to read revision content from pages they lack permission to view.

Key dates

02Disclosure timeline

September 1, 2026 CVE published

Related vulnerabilities

04Related CVE