CVE-2026-52853
Deferred Deferred - Pending Action

Authenticated Workspace Owner Privilege Escalation in Docmost

Vulnerability report for CVE-2026-52853, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-24

Last updated on: 2026-09-24

Assigner: GitHub, Inc.

Description

Docmost is open-source collaborative wiki and documentation software. Prior to 0.90.1, an authenticated workspace ADMIN can use the workspace invitation flow to invite an external email address with the OWNER role because the role ceiling does not prevent ADMIN users from granting privileges above their own. When the invitation is accepted, the new account receives OWNER-level permissions, allowing the ADMIN to create a backdoor OWNER account or promote a colluding external user to the workspace's highest privilege level. This issue is fixed in version 0.90.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-24
Last Modified
2026-09-24
Generated
2026-09-25
AI Q&A
2026-09-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-269 The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Docmost is open-source wiki software. Prior to version 0.90.1, an authenticated workspace admin could invite an external user with the OWNER role through the workspace invitation system. The role ceiling did not prevent admins from granting higher privileges than their own, allowing them to create a backdoor OWNER account or elevate a colluding user to the highest permission level.

Detection Guidance

This vulnerability requires checking Docmost user roles and workspace invitations. Review workspace member lists for unexpected OWNER role assignments. Check audit logs for invitation events with elevated privileges. Verify Docmost version is 0.90.1 or higher to confirm patch status.

Impact Analysis

An attacker with admin access could grant themselves or an accomplice OWNER-level permissions, enabling full control over the workspace. This could lead to unauthorized data access, modification, or deletion, and compromise the entire documentation system.

Compliance Impact

This vulnerability could violate compliance requirements that mandate strict access controls and auditability, such as GDPR's data protection principles or HIPAA's access management rules. Unauthorized privilege escalation risks exposing sensitive data.

Mitigation Strategies

Upgrade Docmost to version 0.90.1 or later to fix the role ceiling issue. Review all workspace members with OWNER privileges and remove any unauthorized accounts. Audit recent invitations and revoke suspicious ones.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-52853. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart