Junglewise Threat Intelligence

CVE-2026-53620: GROWI authorization bypass in bookmark folder APIs

CVE-2026-53620 · Severity: medium · CVSS 6.3 · Published 2026-08-31

Technologies: GROWI.

Executive brief

GROWI is a popular open-source wiki and knowledge management platform. This vulnerability allows an authenticated attacker to retrieve, modify, or delete other users' bookmarks through improper authorization checks in the API, potentially exposing or corrupting sensitive user data stored within the platform.

Technical details

The vulnerability is an authorization bypass (CWE-639) in GROWI's bookmark folder APIs where user-controlled keys are used without proper validation. An authenticated attacker can manipulate API requests to access, modify, or delete bookmark data belonging to other users. The vulnerability requires authentication to exploit but does not require user interaction. The attack is network-accessible. A patch is available in GROWI v8.0.1 and later.

Affected products

  • GROWI GROWI v8.0.0 and earlier

Timeline

  • 2026-08-31: disclosed
  • 2026-08-28: patched: GROWI v8.0.1 released

References