Description
GROWI contains an incorrect authorization vulnerability. If this vulnerability is exploited, an unauthenticated attacker could retrieve the other user's bookmark data.
Published: 2026-08-31
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Confidentiality Breach
Action: Patch Now
AI Analysis

Impact

The vulnerability in GROWI arises from improper authorization checks, allowing an unauthenticated attacker to retrieve bookmark data belonging to other users. This data exposure compromises confidentiality, potentially revealing sensitive user preferences or organizational structures. The flaw is classified as an authorization bypass (CWE-863) and does not involve code execution or integrity compromise.

Affected Systems

The affected platform is GROWI developed by GROWI, Inc. Version information is not specified in the advisory, indicating that all installations of GROWI that have not applied a patch to this authorization fix remain vulnerable.

Risk and Exploitability

The CVSS base score of 6.9 indicates moderate severity. The attack vector is inferred to be remote, as the description mentions an unauthenticated attacker retrieving data, but the specific interface (e.g., web endpoint) is not explicitly stated. EPSS data is not available, and the vulnerability is not listed in CISA’s KEV catalog. Nonetheless, the ability to expose user data without authentication poses a significant privacy risk for environments where GROWI is exposed to external networks.

Generated by OpenCVE AI on August 31, 2026 at 08:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest vendor patch or upgrade to the newest GROWI release that addresses the authorization flaw.
  • Configure the application to enforce authentication before allowing bookmark data requests, ensuring only authenticated users can access this endpoint.
  • Monitor access logs for unauthorized bookmark data access and block any suspicious IP addresses or traffic patterns.

Generated by OpenCVE AI on August 31, 2026 at 08:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 31 Aug 2026 08:45:00 +0000

Type Values Removed Values Added
Title Authorization Bypass Exposes Unauthenticated Bookmark Data

Mon, 31 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
First Time appeared Growi
Growi growi
Vendors & Products Growi
Growi growi

Mon, 31 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Description GROWI contains an incorrect authorization vulnerability. If this vulnerability is exploited, an unauthenticated attacker could retrieve the other user's bookmark data.
Weaknesses CWE-863
References
Metrics cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-08-31T15:37:36.726Z

Reserved: 2026-08-05T01:33:19.073Z

Link: CVE-2026-68951

cve-icon Vulnrichment

Updated: 2026-08-31T15:37:25.217Z

cve-icon NVD

Status : Deferred

Published: 2026-08-31T07:17:45.400

Modified: 2026-08-31T19:33:11.197

Link: CVE-2026-68951

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T08:30:17Z

Weaknesses