CVE-2026-38587: Medium severity Onlyoffice DocSpace vulnerability
An Insecure Direct Object Reference (IDOR) vulnerability was discovered in ONLYOFFICE DocSpace before 3.2.1. The flaw exists in multiple REST API endpoints. This allows authenticated users with low-level permissions (User or Guest) to retrieve sensitive information, such as the Owner's unique identifier (ID) and profile information, which should only be accessible to administrators.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-38587?
The severity of CVE-2026-38587 is rated as medium with a CVSS score of 4.3.
How do I fix CVE-2026-38587?
To fix CVE-2026-38587, upgrade ONLYOFFICE DocSpace to version 3.2.1 or later.
What type of vulnerability is CVE-2026-38587?
CVE-2026-38587 is classified as an Insecure Direct Object Reference (IDOR) vulnerability.
What are the potential impacts of CVE-2026-38587?
CVE-2026-38587 allows authenticated users with low-level permissions to access sensitive information.
Which software is affected by CVE-2026-38587?
CVE-2026-38587 affects ONLYOFFICE DocSpace versions prior to 3.2.1.