An Insecure Direct Object Reference (IDOR) vulnerability was discovered in ONLYOFFICE DocSpace before 3.2.1. The flaw exists in multiple REST API endpoints. This allows authenticated users with low-level permissions (User or Guest) to retrieve sensitive information, such as the Owner's unique identifier (ID) and profile information, which should only be accessible to administrators.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 26 May 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Insecure Direct Object Reference in ONLYOFFICE DocSpace REST API Enables Sensitive Data Exposure for Low-Permission Users | |
| Weaknesses | CWE-639 |
Tue, 26 May 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An Insecure Direct Object Reference (IDOR) vulnerability was discovered in ONLYOFFICE DocSpace before 3.2.1. The flaw exists in multiple REST API endpoints. This allows authenticated users with low-level permissions (User or Guest) to retrieve sensitive information, such as the Owner's unique identifier (ID) and profile information, which should only be accessible to administrators. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-26T14:27:34.283Z
Reserved: 2026-04-06T00:00:00.000Z
Link: CVE-2026-38587
No data.
Status : Received
Published: 2026-05-26T16:16:23.920
Modified: 2026-05-26T16:16:23.920
Link: CVE-2026-38587
No data.
OpenCVE Enrichment
Updated: 2026-05-26T16:30:10Z
Weaknesses
No weakness.