Executive brief
ONLYOFFICE DocSpace is a collaborative platform for managing and editing documents. A security flaw was found where low-level users or guests could access sensitive administrative information, such as profile details and unique identifiers of the system owner. This could lead to unauthorized information disclosure and assist in further targeted attacks against the platform's administrators.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability exists in multiple REST API endpoints of ONLYOFFICE DocSpace prior to version 3.2.1. The vulnerability stems from insufficient authorization checks when accessing specific object identifiers. An authenticated attacker with 'User' or 'Guest' permissions can manipulate API requests to retrieve sensitive data, including the Owner's unique identifier (ID) and profile information, which is intended to be restricted to administrators. The issue is resolved in version 3.2.1.
Affected products
- ONLYOFFICE DocSpace before 3.2.1
Timeline
- 2026-05-26: advisory: CVE-2026-38587 published by NVD
- 2026-05-26: disclosed: Vulnerability disclosed in ONLYOFFICE DocSpace changelog