Junglewise Threat Intelligence

CVE-2026-84204: GROWI access control bypass in attachment API

CVE-2026-84204 · Severity: medium · CVSS 6.5 · Published 2026-09-01

Technologies: GROWI Labs GROWI.

Executive brief

GROWI is a team collaboration and wiki platform. An access control vulnerability in its attachment API allows authenticated users to retrieve metadata about files attached to pages they do not have permission to view. An attacker could use this to discover sensitive documents or attachment information that should be restricted.

Technical details

The vulnerability is an access control bypass (CWE-639) in the GET /_api/v3/attachment/:id endpoint. The endpoint fails to validate whether the authenticated user has permission to access the page associated with a requested attachment. An attacker with valid credentials can enumerate or retrieve attachment metadata by supplying known attachment identifiers, even for pages marked as private or restricted. The vulnerability requires authentication but no special privileges. A fix is available in versions after v8.0.2.

Affected products

  • GROWI Labs GROWI before v8.0.3 (v8.0.2 confirmed vulnerable)

Timeline

  • 2026-09-01: disclosed

References