CVE-2026-33146
MEDIUMDocmost's Public Share Search Exposes Metadata of Restricted Children
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2026-33146. PoCs published by 0xmrma.
AI-analyzed exploit summary This repository provides a detailed technical analysis of CVE-2026-33146, an information disclosure vulnerability in Docmost where restricted child pages hidden from public share viewers could still leak through public share search results. The writeup includes root cause analysis, patch suggestions, and proof-of-concept HTTP requests demonstrating the vulnerability.
Description
Docmost is open-source collaborative wiki and documentation software. An authorization bypass vulnerability in versions 0.70.0 through 0.70.2 exposes restricted child page titles and text snippets through the public search endpoint (`POST /api/search/share-search`) for publicly shared content. This flaw allows unauthenticated users to enumerate and retrieve content that should remain hidden from public share viewers, leading to a confidentiality breach. Version 0.70.3 contains a patch.
Exploits (1)
This repository provides a detailed technical analysis of CVE-2026-33146, an information disclosure vulnerability in Docmost where restricted child pages hidden from public share viewers could still leak through public share search results. The writeup includes root cause analysis, patch suggestions, and proof-of-concept HTTP requests demonstrating the vulnerability.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N