CVE-2026-88817
Privilege escalation via legacy access group creation endpoint
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
An authenticated, non-guest user of Curiosity Workspace could enroll themselves as an administrator and member of an existing access group without an invitation or approval. It did not grant application-wide administrator privileges, and the vulnerability could not be used to obtain root access to the application or its underlying host.
| CWE | CWE-269 CWE-284 |
| Vendor | curiosity gmbh |
| Product | curiosity workspace |
| Published | Sep 16, 2026 |
| Last Updated | Sep 16, 2026 |
Stay Ahead of the Next One
Get instant alerts for curiosity gmbh curiosity workspace
Be the first to know when new unknown vulnerabilities affecting curiosity gmbh curiosity workspace are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Curiosity GmbH / Curiosity Workspace
26.8.70362
References
Credits
DELANNOY Marc-Antoine [Airbus Protect] - <[email protected]>