Impact
An authenticated, non-guest user of Curiosity Workspace can enroll themselves as an administrator and as a member of an existing access group without any invitation or approval process, silently elevating their privileges within that group. The vulnerability does not grant application‑wide administrator rights nor root access to the host system, but it enables unauthorized control over group‑level resources and permissions.
Affected Systems
Curiosity GmbH’s Curiosity Workspace product is affected. Any deployment running a version prior to the patch 26.8.70363 is vulnerable to this privilege‑escalation flaw.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.7, indicating high severity, yet the EPSS score of <1% reflects a low likelihood of exploitation. It is not listed in the CISA KEV catalog. Exploitation requires an authenticated session, so the attack vector is limited to compromised or malicious user accounts within the organization, making it an insider‑or‑credential‑compromise risk rather than a remote public threat.
OpenCVE Enrichment