๐Ÿ” CVE Alert

CVE-2026-88817

UNKNOWN 0.0

Privilege escalation via legacy access group creation endpoint

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

An authenticated, non-guest user of Curiosity Workspace could enroll themselves as an administrator and member of an existing access group without an invitation or approval. It did not grant application-wide administrator privileges, and the vulnerability could not be used to obtain root access to the application or its underlying host.

CWE CWE-269 CWE-284
Vendor curiosity gmbh
Product curiosity workspace
Published Sep 16, 2026
Last Updated Sep 16, 2026
Stay Ahead of the Next One

Get instant alerts for curiosity gmbh curiosity workspace

Be the first to know when new unknown vulnerabilities affecting curiosity gmbh curiosity workspace are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Curiosity GmbH / Curiosity Workspace
26.8.70362

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
docs.curiosity.ai: https://docs.curiosity.ai/security/advisories/cve-2026-88817

Credits

DELANNOY Marc-Antoine [Airbus Protect] - <[email protected]>