Medium severity6.3NVD Advisory· Published Aug 31, 2026
CVE-2026-53620
CVE-2026-53620
Description
GROWI contains a vulnerability with an authorization bypass through user-controlled key in the bookmark folder APIs. If this vulnerability is exploited, an authenticated attacker could retrieve, tamper with, and/or delete the other user's bookmark data.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.