cvedb.io
CVE-2026-34213
MEDIUM · CVSS 5.4
EPSS exploitation probability: 0%
Published 2026-04-14T22:16:31.193 · Last modified 2026-06-17T10:38:39.833

Summary

Docmost is open-source collaborative wiki and documentation software. Starting in version 0.3.0 and prior to version 0.71.0, improper authorization in Docmost allows a low-privileged authenticated user to overwrite another page's attachment within the same workspace by supplying a victim `attachmentId` to `POST /api/files/upload`. This is a remote integrity issue requiring no victim interaction. Version 0.71.0 contains a patch.

Affected products

docmost — docmost

Does this affect you?

Add your gear to cvedb and we'll alert you only when docmost ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.