Executive brief
Sismics Docs (Teedy), an open-source document management system, contains a security flaw that allows unauthorized users to view private documents. By adding a specific keyword to a web request, an attacker can trick the system into granting administrative access to files, comments, and metadata without a password. This could lead to the exposure of sensitive corporate documents and internal communications.
Technical details
An incorrect access control vulnerability exists in Sismics Docs (Teedy) v1.11 due to the unsafe handling of the 'share' query parameter. The 'BaseResource.getTargetIdList' method appends the user-provided 'share' value directly to the ACL target list. Because 'SecurityUtil.skipAclCheck' returns true if the target list contains reserved strings like 'admin' or 'administrators', an attacker can bypass authorization by appending '?share=admin' to read requests. This allows unauthenticated access to document metadata, file downloads, ZIP exports, and comment listings, provided the attacker knows the target document or file identifier.
Affected products
- Sismics Docs (Teedy) 1.11
Timeline
- 2026-06-13: other: Vulnerability details shared via GitHub Gist
- 2026-06-15: disclosed: CVE published to NVD dataset