CVE-2026-38587

MEDIUM

ONLYOFFICE DocSpace < 3.2.1 - Authenticated Insecure Direct Object Reference in REST API

Title source: llm
STIX 2.1

Description

An Insecure Direct Object Reference (IDOR) vulnerability was discovered in ONLYOFFICE DocSpace before 3.2.1. The flaw exists in multiple REST API endpoints. This allows authenticated users with low-level permissions (User or Guest) to retrieve sensitive information, such as the Owner's unique identifier (ID) and profile information, which should only be accessible to administrators.

Scores

CVSS v3 4.3
EPSS 0.0022
EPSS Percentile 12.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-639
Status published
Published May 26, 2026
Tracked Since May 26, 2026