CVE-2026-77165: Medium severity vulnerability
Published Sep 21, 2026
·Updated
File owners were unable to unlock TYPETOKEN locks placed by other users, leaving files permanently locked with no recovery path outside of the database.
Event History
Sep 21, 2026
CVE Published
via MITRE·03:25 PM
Data Sourced
via MITRE·03:25 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
The attacker needs network access and low-privilege authenticated access. Exploitation has low complexity and does not require user interaction.
2
What is the security impact of successful exploitation?
The impact is limited to availability: files can be left permanently locked. The provided vector indicates no confidentiality or integrity impact.
3
Is there a non-database recovery option for affected locks?
No recovery path outside of the database is described. Recovery therefore requires database-level intervention.