CVE-2026-93547
Received Received - Intake

Authorization Bypass in Vaadin Spreadsheet Component

Vulnerability report for CVE-2026-93547, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: Vaadin Ltd.

Description

A missing authorization check in the Vaadin Spreadsheet component allows an authenticated user of an application that renders a spreadsheet to add or replace cell comments on a sheet that has protection enabled, including on cells that are locked. Writing a comment to a cell that does not exist yet also creates the row and the cell. Users of affected versions should apply the following mitigation or upgrade. Releases that have fixed this issue include: Product version Vaadin 23.1.0 - 23.6.13 Vaadin 24.0.0 - 24.9.21 Vaadin 24.10.0 - 24.10.9 Vaadin 25.0.0 - 25.1.11 Vaadin 25.2.0 - 25.2.6 Vaadin Framework 7 and 8 with the Spreadsheet add-on 2.0.0 - 3.1.0 Mitigation Upgrade to 23.6.14 Upgrade to 24.9.22 Upgrade to 24.10.10 Upgrade to 25.1.12 Upgrade to 25.2.7 or newer Upgrade the Spreadsheet add-on to 3.1.1 Please note that Vaadin versions 10-13 and 15-22 are no longer supported and you should update either to the latest 23, 24, 25 version. Artifacts Maven coordinates Vulnerable versions Fixed version com.vaadin:vaadin 23.1.0 - 23.6.13 >=23.6.14 com.vaadin:vaadin 24.0.0 - 24.9.21 >=24.9.22 com.vaadin:vaadin 24.10.0 - 24.10.9 >=24.10.10 com.vaadin:vaadin 25.0.0 - 25.1.11 >=25.1.12 com.vaadin:vaadin 25.2.0 - 25.2.6 >=25.2.7 com.vaadin:vaadin-spreadsheet-flow 23.1.0 - 23.6.13 >=23.6.14 com.vaadin:vaadin-spreadsheet-flow 24.0.0 - 24.9.21 >=24.9.22 com.vaadin:vaadin-spreadsheet-flow 24.10.0 - 24.10.9 >=24.10.10 com.vaadin:vaadin-spreadsheet-flow 25.0.0 - 25.1.11 >=25.1.12 com.vaadin:vaadin-spreadsheet-flow 25.2.0 - 25.2.6 >=25.2.7 com.vaadin:vaadin-spreadsheet 2.0.0 - 3.1.0 >=3.1.1

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 21 associated CPEs
Vendor Product Version / Range
vaadin vaadin From 23.1.0 (inc) to 23.6.13 (inc)
vaadin vaadin From 24.0.0 (inc) to 24.9.21 (inc)
vaadin vaadin From 24.10.0 (inc) to 24.10.9 (inc)
vaadin vaadin From 25.0.0 (inc) to 25.1.11 (inc)
vaadin vaadin From 25.2.0 (inc) to 25.2.6 (inc)
vaadin vaadin-spreadsheet-flow From 23.1.0 (inc) to 23.6.13 (inc)
vaadin vaadin-spreadsheet-flow From 24.0.0 (inc) to 24.9.21 (inc)
vaadin vaadin-spreadsheet-flow From 24.10.0 (inc) to 24.10.9 (inc)
vaadin vaadin-spreadsheet-flow From 25.0.0 (inc) to 25.1.11 (inc)
vaadin vaadin-spreadsheet-flow From 25.2.0 (inc) to 25.2.6 (inc)
vaadin vaadin-spreadsheet From 2.0.0 (inc) to 3.1.0 (inc)
vaadin vaadin 23.1.0
vaadin vaadin to 23.6.14 (exc)
vaadin vaadin 24.0.0
vaadin vaadin to 24.9.22 (exc)
vaadin vaadin 24.10.0
vaadin vaadin 25.0.0
vaadin vaadin to 25.1.12 (exc)
vaadin vaadin 25.2.0
vaadin vaadin spreadsheet
vaadin vaadin to 3.1.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-285 The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a missing authorization check in the Vaadin Spreadsheet component. It allows authenticated users to add or replace cell comments on protected sheets and locked cells without proper validation. The issue occurs because the updateCellComment handler does not verify sheet protection state before modifying cells, unlike other write operations. This can also create empty cells if the target cell does not exist.

Detection Guidance

Detecting this vulnerability requires checking if your Vaadin application uses an affected version of the Spreadsheet component. Review your project dependencies for com.vaadin:vaadin or com.vaadin:vaadin-spreadsheet-flow versions between 23.1.0-23.6.13, 24.0.0-24.9.21, 24.10.0-24.10.9, 25.0.0-25.1.11, or 25.2.0-25.2.6. For Vaadin Framework 7/8, check for vaadin-spreadsheet versions 2.0.0-3.1.0.

Impact Analysis

An attacker could modify comments on protected cells or create empty cells within a spreadsheet. If the workbook is shared or persisted, this could expose sensitive data or disrupt data integrity. The impact is limited to comment integrity and empty cell creation within the user's session.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by allowing unauthorized modifications to protected cells in spreadsheets, which may contain sensitive personal or health data. Unauthorized comment additions or cell modifications could lead to data integrity issues or unintended exposure of confidential information if workbooks are shared or persisted.

Mitigation Strategies
  • Upgrade Vaadin to fixed versions: 23.6.14, 24.9.22, 24.10.10, 25.1.12, or 25.2.7+ depending on your current version.
  • For Vaadin Framework 7/8, upgrade the Spreadsheet add-on to version 3.1.1 or higher.
  • If using unsupported versions (10-13 or 15-22), migrate to the latest supported version (23, 24, or 25).
  • Review and restrict user permissions in your application to minimize exposure if the vulnerability is present.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-93547. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart