High severity7.7NVD Advisory· Published Apr 28, 2026· Updated May 1, 2026
CVE-2026-41649
CVE-2026-41649
Description
Outline is a service that allows for collaborative documentation. The shares.create API endpoint starting in version 0.86.0 and prior to version 1.7.0 has an insecure direct object reference.. When both collectionId and documentId are provided in the request, the authorization logic only checks access to the collection, completely ignoring the document. This allows an authenticated attacker to generate a valid public share link for any document on the platform, including documents belonging to other workspaces. The full document contents can then be retrieved via the documents.info endpoint. Version 1.7.0 contains a patch.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
3- github.com/outline/outline/commit/1b91a295e10f58a1088c54f533773788325ff460nvdPatch
- github.com/outline/outline/security/advisories/GHSA-23jj-rp48-w7q7nvdExploitVendor Advisory
- github.com/outline/outline/releases/tag/v1.7.0nvdRelease Notes
News mentions
0No linked articles in our index yet.