🔐 CVE Alert

CVE-2026-43889

MEDIUM 6.5

Outline: Unauthorized Document Publication via Mixed collectionId+documentId Share

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
12th

Outline is a service that allows for collaborative documentation. Prior to 1.7.0, the shares.create API accepts both collectionId and documentId simultaneously and, when published=false, only verifies read access for each—skipping the "share" permission check. A subsequent shares.update authorizes publication using an OR policy (can share collection OR can share document), so an attacker who holds share permission on one unrelated collection can publish a share that exposes an arbitrary document they cannot legitimately share, making it publicly accessible to unauthenticated users. This vulnerability is fixed in 1.7.0.

CWE CWE-863
Vendor outline
Product outline
Published May 11, 2026
Last Updated May 12, 2026
Stay Ahead of the Next One

Get instant alerts for outline outline

Be the first to know when new medium vulnerabilities affecting outline outline are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

outline / outline
< 1.7.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/outline/outline/security/advisories/GHSA-rg4j-pmch-w6pm