CVE-2026-68951: Medium severity GROWI vulnerability
Published Aug 31, 2026
·Updated
GROWI contains an incorrect authorization vulnerability. If this vulnerability is exploited, an unauthenticated attacker could retrieve the other user's bookmark data.
Affected Software
1 affected component
GROWI
Event History
Aug 31, 2026
CVE Published
via MITRE·06:31 AM
Data Sourced
via MITRE·06:31 AM
DescriptionSeverity
Frequently Asked Questions
1
Who can exploit this issue?
An unauthenticated attacker can exploit the incorrect authorization issue over the network. No privileges or user interaction are required.
2
What information could be exposed?
The issue could allow retrieval of another user's bookmark data. The provided information indicates confidentiality impact only, with no integrity or availability impact described.