Junglewise Threat Intelligence

CVE-2026-35023: Wimi Teamwork On-Premises IDOR in preview.php

CVE-2026-35023 · Severity: medium · CVSS 4.3 · Published 2026-04-08

Executive brief

Wimi Teamwork On-Premises, a collaborative project management platform, contains a security flaw that allows users to view images from private conversations they are not part of. By manipulating identification numbers in the application's preview feature, an authorized user can systematically access and download image previews from other users' private or group chats. This could lead to the unauthorized disclosure of sensitive business information or personal data shared within the organization.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability exists in Wimi Teamwork On-Premises versions prior to 8.2.0. The vulnerability is located in the `preview.php` endpoint, where the `item_id` parameter is processed without adequate authorization checks to ensure the requesting user has permission to view the associated content. An authenticated attacker can exploit this by enumerating sequential `item_id` values via network requests to retrieve image previews from private or group conversations belonging to other users. The issue was addressed in version 8.2.0.

Affected products

  • Wimi Teamwork On-Premises < 8.2.0

Timeline

  • 2026-01-25: patched: Version 8.2.0 released with security fixes.
  • 2026-04-08: disclosed: Initial vulnerability disclosure.
  • 2026-04-08: advisory

References