Description
Documenso 2.17.0 contains an access control vulnerability in the PDF-serving endpoint that fails to validate document visibility settings. Attackers with low privileges can read restricted documents within their team or cross-tenant by leveraging missing ownership validation on document data identifiers.
Published: 2026-09-04
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access to Confidential Documents
Action: Apply Patch
AI Analysis

Impact

Documenso 2.17.0 implements a PDF-serving endpoint that does not enforce document visibility settings. The missing validation allows an authenticated user with low privileges to request and download PDFs that are marked as restricted or belong to another team. The impact is that sensitive content can be accessed by individuals who should not have permission based on ownership or team boundaries, violating confidentiality and potentially regulatory requirements.

Affected Systems

The affected product is Documenso 2.17.0. All installations of this specific release are vulnerable as the flaw exists in the server‑side PDF helper code referenced in the repository.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.1, indicating a high severity of exploitation. EPSS data is not available, so the likelihood cannot be quantified, but the flaw is publicly described and the path is straightforward: a legitimate authenticated user can send a request to the PDF endpoint with a document identifier that bypasses ownership checks. The flaw is not listed in the CISA KEV catalog, yet the lack of access control makes it attractive to attackers who can exploit cross‑tenant data leakage.

Generated by OpenCVE AI on September 4, 2026 at 15:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to a patched version of Documenso that includes a fix for the PDF route visibility validation.
  • If a patch is not yet available, temporarily disable the public PDF‑serving endpoint or restrict it to administrators only until the fix is applied.
  • Add an additional ownership or team check in the PDF generation logic before sending the file to ensure that only the document owner or authorized team members can access the content.

Generated by OpenCVE AI on September 4, 2026 at 15:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Documenso
Documenso documenso
Vendors & Products Documenso
Documenso documenso

Fri, 04 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Documenso 2.17.0 contains an access control vulnerability in the PDF-serving endpoint that fails to validate document visibility settings. Attackers with low privileges can read restricted documents within their team or cross-tenant by leveraging missing ownership validation on document data identifiers.
Title Documenso 2.17.0 PDF Route Ignores Document Visibility
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Documenso Documenso
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-04T17:42:57.629Z

Reserved: 2026-09-04T13:51:52.593Z

Link: CVE-2026-85697

cve-icon Vulnrichment

Updated: 2026-09-04T17:42:53.994Z

cve-icon NVD

Status : Received

Published: 2026-09-04T15:17:48.670

Modified: 2026-09-04T18:18:06.913

Link: CVE-2026-85697

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T18:30:04Z

Weaknesses