CVE-2026-88817: Privilege escalation via legacy access group creation endpoint
An authenticated, non-guest user of Curiosity Workspace could enroll themselves as an administrator and member of an existing access group without an invitation or approval.
It did not grant application-wide administrator privileges, and the vulnerability could not be used to obtain root access to the application or its underlying host.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Curiosity Workplaceto a version that resolves this vulnerability.Fixed in 26.8.70363
Event History
Frequently Asked Questions
Who could exploit this issue?
An authenticated Curiosity Workspace user who was not a guest could exploit it. Guest users were not within the described attack prerequisite.
What level of access could an attacker gain?
An attacker could add themselves as an administrator and member of an existing access group. The issue did not provide application-wide administrator privileges or root access to the application or its underlying host.
What would an attacker need before attempting exploitation?
They would need a valid authenticated non-guest account and an existing access group to target. No invitation or approval from that group was required.