Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 27 May 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Onlyoffice
Onlyoffice docspace |
|
| Vendors & Products |
Onlyoffice
Onlyoffice docspace |
Tue, 26 May 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Insecure Direct Object Reference in ONLYOFFICE DocSpace REST API Enables Sensitive Data Exposure for Low-Permission Users |
Tue, 26 May 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 26 May 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Insecure Direct Object Reference in ONLYOFFICE DocSpace REST API Enables Sensitive Data Exposure for Low-Permission Users | |
| Weaknesses | CWE-639 |
Tue, 26 May 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An Insecure Direct Object Reference (IDOR) vulnerability was discovered in ONLYOFFICE DocSpace before 3.2.1. The flaw exists in multiple REST API endpoints. This allows authenticated users with low-level permissions (User or Guest) to retrieve sensitive information, such as the Owner's unique identifier (ID) and profile information, which should only be accessible to administrators. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-26T20:07:07.679Z
Reserved: 2026-04-06T00:00:00.000Z
Link: CVE-2026-38587
Updated: 2026-05-26T20:06:58.823Z
Status : Deferred
Published: 2026-05-26T16:16:23.920
Modified: 2026-06-17T10:41:44.470
Link: CVE-2026-38587
No data.
OpenCVE Enrichment
Updated: 2026-05-27T10:05:42Z