Medium severity5.3NVD Advisory· Published Sep 28, 2026
CVE-2026-101004
CVE-2026-101004
Description
A security vulnerability has been detected in notionnext-org NotionNext up to 4.10.10. Affected by this issue is the function cleanCache of the file pages/api/cache.js of the component Authentication Guard. The manipulation of the argument token leads to missing authentication. The attack may be initiated remotely. Versions 4.1.0 - 4.9.5.2 allow unauthenticated exploitation due to missing method check. In versions 4.9.5.7 - 4.10.10 a guard present but only enforced when CACHE_REVALIDATION_TOKEN is set. Default deployments remain unprotected. The vendor was contacted early about this disclosure but did not respond in any way.
Affected products
1- Range: up to 4.10.10, specifically 4.1.0 - 4.9.5.2 and 4.9.5.7 - 4.10.10
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.