VYPR
High severity7.7NVD Advisory· Published Apr 28, 2026· Updated May 1, 2026

CVE-2026-41649

CVE-2026-41649

Description

Outline is a service that allows for collaborative documentation. The shares.create API endpoint starting in version 0.86.0 and prior to version 1.7.0 has an insecure direct object reference.. When both collectionId and documentId are provided in the request, the authorization logic only checks access to the collection, completely ignoring the document. This allows an authenticated attacker to generate a valid public share link for any document on the platform, including documents belonging to other workspaces. The full document contents can then be retrieved via the documents.info endpoint. Version 1.7.0 contains a patch.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Outline/Outline2 versions
    cpe:2.3:a:getoutline:outline:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:getoutline:outline:*:*:*:*:*:*:*:*range: >=0.86.0,<1.7.0
    • (no CPE)range: >=0.86.0, <1.7.0

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.