๐Ÿ” CVE Alert

CVE-2026-84204

MEDIUM 6.5

GROWI through 8.0.2 Missing Authorization on apiv3 Attachment Retrieval

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

GROWI contains an access control vulnerability in the GET /_api/v3/attachment/:id endpoint that fails to validate page access permissions. Authenticated attackers can retrieve attachment metadata from pages they cannot view by supplying known attachment identifiers.

CWE CWE-862
Vendor growilabs
Product growi
Published Sep 1, 2026
Last Updated Sep 1, 2026
Stay Ahead of the Next One

Get instant alerts for growilabs growi

Be the first to know when new medium vulnerabilities affecting growilabs growi are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

growilabs / growi
0 โ‰ค 8.0.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/growilabs/growi github.com: https://github.com/growilabs/growi/pull/11810 github.com: https://github.com/growilabs/growi/commit/d298e0b1dbbf568c99db657fa0f7e90f72ddc59b github.com: https://github.com/growilabs/growi/blob/v8.0.2/apps/app/src/server/routes/apiv3/attachment.js vulncheck.com: https://www.vulncheck.com/advisories/growi-through-8.0.2-missing-authorization-on-apiv3-attachment-retrieval

Credits

Dilipkumar Choudhary