Junglewise Threat Intelligence

CVE-2026-68951: GROWI incorrect authorization in bookmark APIs

CVE-2026-68951 · Severity: medium · CVSS 5.3 · Published 2026-08-31

Technologies: GROWI, Inc. GROWI.

Executive brief

GROWI is a collaborative knowledge management and documentation platform used to store and organize team information. This vulnerability allows unauthenticated attackers to retrieve other users' bookmark data without proper authorization checks, potentially exposing sensitive saved references and organizational information.

Technical details

The vulnerability is an incorrect authorization flaw (CWE-863) in GROWI's bookmark listing APIs. An unauthenticated attacker can retrieve other users' bookmark data due to missing authorization checks on the bookmark API endpoints. The attack vector is network-based and requires no authentication, user interaction, or special preconditions—any remote attacker can directly access the vulnerable API. The impact is limited to confidentiality: attackers can read bookmark data of other users. A patch is available in GROWI v8.0.1.

Affected products

  • GROWI, Inc. GROWI v8.0.0 and earlier

Timeline

  • 2026-08-28: disclosed
  • 2026-08-31: advisory
  • 2026-08-28: patched: GROWI v8.0.1 released

References