CVE-2026-85697: Documenso 2.17.0 PDF Route Ignores Document Visibility
Published Sep 4, 2026
·Updated
Documenso 2.17.0 contains an access control vulnerability in the PDF-serving endpoint that fails to validate document visibility settings. Attackers with low privileges can read restricted documents within their team or cross-tenant by leveraging missing ownership validation on document data identifiers.
Affected Software
1 affected component
Documenso=2.17.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Documensoto a version that resolves this vulnerability.Fixed in 2.17.0
Event History
Sep 4, 2026
CVE Published
via MITRE·02:32 PM
Data Sourced
via MITRE·02:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does exploitation require an existing authenticated account?
Yes. The attacker must have low-level privileges; no user interaction is required.
2
Can a low-privileged user access data outside their own team?
Yes. The affected endpoint may allow restricted-document access within the attacker’s team and across tenants when document data identifiers are used without ownership validation.