๐Ÿ” CVE Alert

CVE-2026-93547

UNKNOWN 0.0

Missing Authorization Check in Vaadin Spreadsheet Allows Cell Comments to Be Written to Protected Sheets and Locked Cells

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

A missing authorization check in the Vaadin Spreadsheet component allows an authenticated user of an application that renders a spreadsheet to add or replace cell comments on a sheet that has protection enabled, including on cells that are locked. Writing a comment to a cell that does not exist yet also creates the row and the cell. Users of affected versions should apply the following mitigation or upgrade. Releases that have fixed this issue include: Product version Vaadin 23.1.0 - 23.6.13 Vaadin 24.0.0 - 24.9.21 Vaadin 24.10.0 - 24.10.9 Vaadin 25.0.0 - 25.1.11 Vaadin 25.2.0 - 25.2.6 Vaadin Framework 7 and 8 with the Spreadsheet add-on 2.0.0 - 3.1.0 Mitigation Upgrade to 23.6.14 Upgrade to 24.9.22 Upgrade to 24.10.10 Upgrade to 25.1.12 Upgrade to 25.2.7 or newer Upgrade the Spreadsheet add-on to 3.1.1 Please note that Vaadin versions 10-13 and 15-22 are no longer supported and you should update either to the latest 23, 24, 25 version. Artifacts Maven coordinates Vulnerable versions Fixed version com.vaadin:vaadin 23.1.0 - 23.6.13 >=23.6.14 com.vaadin:vaadin 24.0.0 - 24.9.21 >=24.9.22 com.vaadin:vaadin 24.10.0 - 24.10.9 >=24.10.10 com.vaadin:vaadin 25.0.0 - 25.1.11 >=25.1.12 com.vaadin:vaadin 25.2.0 - 25.2.6 >=25.2.7 com.vaadin:vaadin-spreadsheet-flow 23.1.0 - 23.6.13 >=23.6.14 com.vaadin:vaadin-spreadsheet-flow 24.0.0 - 24.9.21 >=24.9.22 com.vaadin:vaadin-spreadsheet-flow 24.10.0 - 24.10.9 >=24.10.10 com.vaadin:vaadin-spreadsheet-flow 25.0.0 - 25.1.11 >=25.1.12 com.vaadin:vaadin-spreadsheet-flow 25.2.0 - 25.2.6 >=25.2.7 com.vaadin:vaadin-spreadsheet 2.0.0 - 3.1.0 >=3.1.1

CWE CWE-285
Vendor vaadin
Product vaadin
Published Sep 30, 2026
Last Updated Sep 30, 2026
Stay Ahead of the Next One

Get instant alerts for vaadin vaadin

Be the first to know when new unknown vulnerabilities affecting vaadin vaadin are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

vaadin / vaadin
23.1.0 < 23.6.14 24.0.0 < 24.9.22 24.10.0 < 24.10.10 25.0.0 < 25.1.12 25.2.0 < 25.2.7
vaadin / vaadin-spreadsheet-flow
23.1.0 < 23.6.14 24.0.0 < 24.9.22 24.10.0 < 24.10.10 25.0.0 < 25.1.12 25.2.0 < 25.2.7
vaadin / vaadin-spreadsheet
2.0.0 < 3.1.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vaadin.com: https://vaadin.com/security/cve-2026-93547 github.com: https://github.com/vaadin/flow-components/pull/9905 github.com: https://github.com/vaadin/flow-components/pull/9907 github.com: https://github.com/vaadin/flow-components/pull/9908 github.com: https://github.com/vaadin/flow-components/pull/9909 github.com: https://github.com/vaadin/flow-components/pull/9910 github.com: https://github.com/vaadin/flow-components/pull/9956 github.com: https://github.com/vaadin/spreadsheet/pull/866

Credits

Arpit Jain