๐Ÿ” CVE Alert

CVE-2026-84205

MEDIUM 6.5

GROWI through 8.0.2 Authorization Bypass Through User-Controlled Key on apiv3 Revision Retrieval

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

GROWI contains an access control vulnerability in the GET /_api/v3/revisions/:id endpoint that validates access against a query parameter but returns the revision identified by the path parameter without confirming they reference the same page. Authenticated attackers can pair a page identifier they can access with an arbitrary revision identifier to read revision content from pages they lack permission to view.

CWE CWE-639
Vendor growilabs
Product growi
Published Sep 1, 2026
Stay Ahead of the Next One

Get instant alerts for growilabs growi

Be the first to know when new medium vulnerabilities affecting growilabs growi are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

growilabs / growi
0 โ‰ค 8.0.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/growilabs/growi github.com: https://github.com/growilabs/growi/pull/11810 github.com: https://github.com/growilabs/growi/commit/d298e0b1dbbf568c99db657fa0f7e90f72ddc59b github.com: https://github.com/growilabs/growi/blob/v8.0.2/apps/app/src/server/routes/apiv3/revisions.js vulncheck.com: https://www.vulncheck.com/advisories/growi-through-8.0.2-authorization-bypass-through-user-controlled-key-on-apiv3-revision-retrieval

Credits

Dilipkumar Choudhary