CVE-2026-33146

MEDIUM

Docmost's Public Share Search Exposes Metadata of Restricted Children

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-33146. PoCs published by 0xmrma.

AI-analyzed exploit summary This repository provides a detailed technical analysis of CVE-2026-33146, an information disclosure vulnerability in Docmost where restricted child pages hidden from public share viewers could still leak through public share search results. The writeup includes root cause analysis, patch suggestions, and proof-of-concept HTTP requests demonstrating the vulnerability.

Description

Docmost is open-source collaborative wiki and documentation software. An authorization bypass vulnerability in versions 0.70.0 through 0.70.2 exposes restricted child page titles and text snippets through the public search endpoint (`POST /api/search/share-search`) for publicly shared content. This flaw allows unauthenticated users to enumerate and retrieve content that should remain hidden from public share viewers, leading to a confidentiality breach. Version 0.70.3 contains a patch.

Exploits (1)

nomisec WRITEUP
by 0xmrma · poc
https://github.com/0xmrma/CVE-2026-33146

This repository provides a detailed technical analysis of CVE-2026-33146, an information disclosure vulnerability in Docmost where restricted child pages hidden from public share viewers could still leak through public share search results. The writeup includes root cause analysis, patch suggestions, and proof-of-concept HTTP requests demonstrating the vulnerability.

Classification
Writeup 100%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Docmost (version not specified)
No auth needed
Prerequisites: valid public share key · subpages included in the share · knowledge of search terms likely to appear in hidden descendants
mistral-large-3 · analyzed Jun 26, 2026 Full analysis →

References (1)

Core 1
Core References

Scores

CVSS v3 4.3
EPSS 0.0027
EPSS Percentile 19.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-285
Status published
Products (2)
docmost/docmost 0.70.0 - 0.70.3
docmost/docmost >= 0.70.0, < 0.70.3
Published Apr 14, 2026
Tracked Since Apr 15, 2026