๐Ÿ” CVE Alert

CVE-2026-41649

HIGH 7.7

Outline has IDOR in document share creation that allows unauthorized access to private documents across workspaces

CVSS Score
7.7
EPSS Score
0.0%
EPSS Percentile
0th

Outline is a service that allows for collaborative documentation. The `shares.create` API endpoint starting in version 0.86.0 and prior to version 1.7.0 has an insecure direct object reference.. When both `collectionId` and `documentId` are provided in the request, the authorization logic only checks access to the collection, completely ignoring the document. This allows an authenticated attacker to generate a valid public share link for any document on the platform, including documents belonging to other workspaces. The full document contents can then be retrieved via the `documents.info` endpoint. Version 1.7.0 contains a patch.

CWE CWE-639
Vendor outline
Product outline
Published Apr 28, 2026
Stay Ahead of the Next One

Get instant alerts for outline outline

Be the first to know when new high vulnerabilities affecting outline outline are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

outline / outline
>= 0.86.0, < 1.7.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/outline/outline/security/advisories/GHSA-23jj-rp48-w7q7 github.com: https://github.com/outline/outline/commit/1b91a295e10f58a1088c54f533773788325ff460 github.com: https://github.com/outline/outline/releases/tag/v1.7.0