Docs before 5.4.1 fails to properly revoke websocket collaboration connections when access is revoked at parent documents. Attackers with revoked access can retain real-time read and write access to sub-documents through open websocket sessions that are never disconnected.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 16 Sep 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Docs before 5.4.1 fails to properly revoke websocket collaboration connections when access is revoked at parent documents. Attackers with revoked access can retain real-time read and write access to sub-documents through open websocket sessions that are never disconnected. | |
| Title | Docs before 5.4.1 Stale Collaboration Session After Access Revocation | |
| Weaknesses | CWE-613 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-16T20:32:51.118Z
Reserved: 2026-09-16T19:47:13.148Z
Link: CVE-2026-92800
No data.
Status : Received
Published: 2026-09-16T21:17:29.533
Modified: 2026-09-16T21:17:29.533
Link: CVE-2026-92800
No data.
OpenCVE Enrichment
No data.
Weaknesses