Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 04 Sep 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Documenso
Documenso documenso |
|
| Vendors & Products |
Documenso
Documenso documenso |
Fri, 04 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 04 Sep 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Documenso 2.17.0 contains an access control vulnerability in the PDF-serving endpoint that fails to validate document visibility settings. Attackers with low privileges can read restricted documents within their team or cross-tenant by leveraging missing ownership validation on document data identifiers. | |
| Title | Documenso 2.17.0 PDF Route Ignores Document Visibility | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-04T17:42:57.629Z
Reserved: 2026-09-04T13:51:52.593Z
Link: CVE-2026-85697
Updated: 2026-09-04T17:42:53.994Z
Status : Received
Published: 2026-09-04T15:17:48.670
Modified: 2026-09-04T18:18:06.913
Link: CVE-2026-85697
No data.
OpenCVE Enrichment
Updated: 2026-09-04T18:30:04Z
