Technology · Jigsaw
Jigsaw Outline vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 8 vulnerabilities in Jigsaw Outline: 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-54573, was published on 25 June 2026.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 0
- Exploited in the wild
- 0
About Jigsaw Outline
Outline is an open-source tool that allows users to set up and manage their own virtual private network (VPN) servers.
Latest Jigsaw Outline vulnerabilities
- CVE-2026-54573: Outline authorization bypass via path parsing discrepancyinfoCVSS 5.3
- CVE-2026-44695: Outline account linking bypass in Slack integration callbackmediumCVSS 5.8EPSS 0.0%
- CVE-2026-43890: Outline IDOR in subscriptions.create API endpointhighCVSS 7.7
- CVE-2026-43889: Outline incorrect authorization in shares.create APImediumCVSS 6.5
- CVE-2026-43888: Outline path traversal via path length truncation in ZipHelperhighCVSS 8.7
- CVE-2026-43887: Outline stored XSS in comment mentionshighCVSS 7.3EPSS 0.0%
- CVE-2026-43886: Outline privilege escalation via OAuth scope wildcard smugglinghighCVSS 8.2
- CVE-2026-41649: Outline IDOR in shares.create API allows cross-workspace document accesshighCVSS 7.7EPSS 0.3%
Most severe Jigsaw Outline vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-43888: Outline path traversal via path length truncation in ZipHelperhighCVSS 8.7
- CVE-2026-43886: Outline privilege escalation via OAuth scope wildcard smugglinghighCVSS 8.2
- CVE-2026-41649: Outline IDOR in shares.create API allows cross-workspace document accesshighCVSS 7.7EPSS 0.3%
- CVE-2026-43890: Outline IDOR in subscriptions.create API endpointhighCVSS 7.7
- CVE-2026-43887: Outline stored XSS in comment mentionshighCVSS 7.3EPSS 0.0%
- CVE-2026-43889: Outline incorrect authorization in shares.create APImediumCVSS 6.5
- CVE-2026-44695: Outline account linking bypass in Slack integration callbackmediumCVSS 5.8EPSS 0.0%
- CVE-2026-54573: Outline authorization bypass via path parsing discrepancyinfoCVSS 5.3
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/outline.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Jigsaw Outline vulnerabilities", https://junglewise.ai/threats/technologies/outline, 26 September 2026.