CVE-2026-33146: Docmost's Public Share Search Exposes Metadata of Restricted Children
Docmost is open-source collaborative wiki and documentation software. An authorization bypass vulnerability in versions 0.70.0 through 0.70.2 exposes restricted child page titles and text snippets through the public search endpoint (POST /api/search/share-search) for publicly shared content. This flaw allows unauthenticated users to enumerate and retrieve content that should remain hidden from public share viewers, leading to a confidentiality breach. Version 0.70.3 contains a patch.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Docmostto a version that resolves this vulnerability.Fixed in 0.70.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33146?
CVE-2026-33146 has been categorized as a moderate severity vulnerability due to its potential for unauthorized exposure of restricted metadata.
How do I fix CVE-2026-33146?
To fix CVE-2026-33146, upgrade Docmost to version 0.70.3 or later, where the authorization bypass vulnerability is resolved.
What software versions are affected by CVE-2026-33146?
CVE-2026-33146 affects Docmost versions 0.70.0 through 0.70.2.
What impact does CVE-2026-33146 have on user data?
CVE-2026-33146 allows the exposure of restricted child page titles and text snippets, potentially compromising sensitive information.
Who is at risk from CVE-2026-33146?
Users of Docmost who have not upgraded to version 0.70.3 or later are at risk from CVE-2026-33146.