CVE-2026-85697
nicheIncorrect authorization in Documenso PDF endpoint leaks restricted documents
Documenso 2.17.0 contains an access control flaw (CWE-863, incorrect authorization) in the endpoint that serves PDF documents: it fails to validate document visibility settings and does not verify that the requester owns or is authorized to view the document being requested. A low-privileged authenticated user who knows or guesses a document's data identifier can request that document's PDF and retrieve it even when visibility settings should restrict it, including documents in other teams or tenants. The attacker gains read access to restricted signed documents, a confidentiality-only impact, with no ability to modify or disrupt anything (CVSS 4.0 confidentiality impact is high while integrity and availability impacts are none). Any organization running Documenso 2.17.0, particularly multi-team or multi-tenant deployments where documents are meant to be team-restricted, is exposed. There is no public proof-of-concept, the issue is not in CISA KEV, and EPSS puts 30-day exploitation probability at just 0.3% (23rd percentile), so no exploitation is currently known.
What to do: Upgrade to the latest Documenso release beyond 2.17.0 as soon as a patched build is available, and monitor the vendor's GitHub security advisories for the fixed version since the advisory data does not name one. In the meantime, restrict and audit access to the PDF-serving endpoint, review team/tenant document sharing and visibility settings, and check access logs for low-privileged accounts fetching documents outside their team or tenant.
| Documenso | 2.17.0 (specific affected range and fixed version not stated in the available advisory data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Documenso 2.17.0 contains an access control vulnerability in the PDF-serving endpoint that fails to validate document visibility settings. Attackers with low privileges can read restricted documents within their team or cross-tenant by leveraging missing ownership validation on document data identifiers.
- Weakness
- CWE-863
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.