CVE-2026-33146
MEDIUMDocmost's Public Share Search Exposes Metadata of Restricted Children
Title source: cnaDescription
Docmost is open-source collaborative wiki and documentation software. An authorization bypass vulnerability in versions 0.70.0 through 0.70.2 exposes restricted child page titles and text snippets through the public search endpoint (`POST /api/search/share-search`) for publicly shared content. This flaw allows unauthenticated users to enumerate and retrieve content that should remain hidden from public share viewers, leading to a confidentiality breach. Version 0.70.3 contains a patch.
Scores
CVSS v3
4.3
EPSS
0.0005
EPSS Percentile
14.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-285
Status
published
Products (2)
docmost/docmost
0.70.0 - 0.70.3
docmost/docmost
>= 0.70.0, < 0.70.3
Published
Apr 14, 2026
Tracked Since
Apr 15, 2026