VYPR
Medium severity6.5NVD Advisory· Published Sep 1, 2026

CVE-2026-84205

CVE-2026-84205

Description

GROWI contains an access control vulnerability in the GET /_api/v3/revisions/:id endpoint that validates access against a query parameter but returns the revision identified by the path parameter without confirming they reference the same page. Authenticated attackers can pair a page identifier they can access with an arbitrary revision identifier to read revision content from pages they lack permission to view.

Affected products

2
  • Growilabs/Growireferences2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: <8.0.2

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.