Impact
Documenso 2.17.0 implements a PDF-serving endpoint that does not enforce document visibility settings. The missing validation allows an authenticated user with low privileges to request and download PDFs that are marked as restricted or belong to another team. The impact is that sensitive content can be accessed by individuals who should not have permission based on ownership or team boundaries, violating confidentiality and potentially regulatory requirements.
Affected Systems
The affected product is Documenso 2.17.0. All installations of this specific release are vulnerable as the flaw exists in the server‑side PDF helper code referenced in the repository.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.1, indicating a high severity of exploitation. EPSS data is not available, so the likelihood cannot be quantified, but the flaw is publicly described and the path is straightforward: a legitimate authenticated user can send a request to the PDF endpoint with a document identifier that bypasses ownership checks. The flaw is not listed in the CISA KEV catalog, yet the lack of access control makes it attractive to attackers who can exploit cross‑tenant data leakage.
OpenCVE Enrichment