VYPR

Docspace

by ONLYOFFICE

Source repositories

CVEs (1)

  • CVE-2026-38587May 26, 2026
    risk 0.00cvss epss

    An Insecure Direct Object Reference (IDOR) vulnerability was discovered in ONLYOFFICE DocSpace before 3.2.1. The flaw exists in multiple REST API endpoints. This allows authenticated users with low-level permissions (User or Guest) to retrieve sensitive information, such as the…