Junglewise Threat Intelligence

CVE-2026-33146: Docmost authorization bypass in public search endpoint

CVE-2026-33146 · Severity: medium · CVSS 4.3 · Published 2026-04-14

Technologies: Docmost. Vendors: Docmost.

Executive brief

Docmost is an open-source platform used by organizations to create and manage collaborative wikis and documentation. A security flaw in the public search feature allows unauthorized users to see titles and text snippets from private pages that were intended to be hidden. This could lead to the exposure of sensitive internal information or project details to anyone with a link to a publicly shared document.

Technical details

An authorization bypass vulnerability exists in Docmost versions 0.70.0 through 0.70.2 within the public search functionality. When a page is shared publicly with the 'includeSubPages' option enabled, the search endpoint (`POST /api/search/share-search`) utilizes a traversal method that fails to filter out restricted descendant pages. An unauthenticated attacker with access to a public share link can craft search queries to enumerate and retrieve metadata, including titles and content snippets, from these restricted child pages. The root cause is located in the search controller and service components which do not implement restricted-aware traversal. This issue is resolved in version 0.70.3.

Affected products

  • Docmost Docmost >= 0.70.0, < 0.70.3

Timeline

  • 2026-04-14: disclosed
  • 2026-04-14: advisory
  • 2026-04-14: patched: Fixed in version 0.70.3

References

Related threats