CVE-2026-92800: Docs before 5.4.1 Stale Collaboration Session After Access Revocation

Published Sep 16, 2026
·
Updated

Docs before 5.4.1 fails to properly revoke websocket collaboration connections when access is revoked at parent documents. Attackers with revoked access can retain real-time read and write access to sub-documents through open websocket sessions that are never disconnected.

Affected Software

1 affected component
Docs<5.4.1

Event History

Sep 16, 2026
CVE Published
via MITRE·08:32 PM
Data Sourced
via MITRE·08:32 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Deployments running Docs before 5.4.1 are affected when users collaborate through websocket sessions on sub-documents and their access can be revoked at a parent-document level.

2

What does an attacker need to exploit it?

The attacker needs prior authorized access that has been revoked, plus an already-open websocket collaboration session. The issue does not describe exploitation by an unauthenticated user or by a user without an existing session.

3

How can I tell whether access revocation has failed?

After revoking a user's access at a parent document, check whether that user's existing websocket session remains connected and can still read or write associated sub-documents in real time.

4

What should be prioritized if an immediate upgrade is not possible?

Prioritize terminating existing websocket collaboration sessions for users whose access has been revoked, since the described impact depends on sessions that remain open after revocation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203