VYPR
Unrated severityNVD Advisory· Published May 26, 2026

CVE-2026-38587

CVE-2026-38587

Description

An Insecure Direct Object Reference (IDOR) vulnerability was discovered in ONLYOFFICE DocSpace before 3.2.1. The flaw exists in multiple REST API endpoints. This allows authenticated users with low-level permissions (User or Guest) to retrieve sensitive information, such as the Owner's unique identifier (ID) and profile information, which should only be accessible to administrators.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

ONLYOFFICE DocSpace before 3.2.1 contains an IDOR vulnerability allowing low-privileged users to read the Owner's profile information via multiple REST API endpoints.

Vulnerability

An Insecure Direct Object Reference (IDOR) vulnerability exists in ONLYOFFICE DocSpace prior to version 3.2.1 [1]. The flaw resides in multiple REST API endpoints that fail to enforce proper authorization checks. Authenticated users with low-level roles such as "User" or "Guest" can bypass access controls to retrieve sensitive information about the portal Owner, including their unique identifier (ID) and profile details.

Exploitation

An attacker must have a valid authenticated session with at least Guest-level permissions. No special privileges or additional prerequisites are required. By crafting direct requests to the vulnerable REST API endpoints, the attacker can enumerate the Owner's personal data without triggering any administrative review or audit mechanism.

Impact

Successful exploitation results in unauthorized disclosure of the Owner's ID and profile information. This violates the principle of least privilege and can lead to further targeted attacks, such as social engineering or account enumeration. The confidentiality of the highest-privilege user is compromised, potentially exposing the portal to broader security risks.

Mitigation

The vulnerability is fixed in ONLYOFFICE DocSpace version 3.2.1 [1]. Users should upgrade to this release or later as soon as possible. No official workaround has been provided for older, unsupported versions. The issue is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog as of the publication date.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.