Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 04 Sep 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Documenso 2.17.0 contains an access control vulnerability in the PDF-serving endpoint that fails to validate document visibility settings. Attackers with low privileges can read restricted documents within their team or cross-tenant by leveraging missing ownership validation on document data identifiers. | |
| Title | Documenso 2.17.0 PDF Route Ignores Document Visibility | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-04T14:32:39.491Z
Reserved: 2026-09-04T13:51:52.593Z
Link: CVE-2026-85697
No data.
Status : Received
Published: 2026-09-04T15:17:48.670
Modified: 2026-09-04T15:17:48.670
Link: CVE-2026-85697
No data.
OpenCVE Enrichment
No data.