CVE-2026-88817
—Improper Access Control in Curiosity Workspace Lets Users Self-Enroll into Admin Groups
CVE-2026-88817 is an improper access-control flaw in Curiosity Workspace in which any authenticated, non-guest user can enroll themselves as an administrator and member of an existing access group without receiving an invitation or approval, indicating a missing authorization check on the group-enrollment function. An attacker triggers it simply by authenticating with a valid standard (non-guest) account and issuing a self-enrollment request to join a targeted group. The attacker gains administrative/member privileges within that access group, potentially exposing or allowing modification of the content and resources shared with that group, though the flaw does not confer application-wide administrator rights or root access to the application or its host. Any organization running Curiosity Workspace with non-guest user accounts is affected. There is no known exploitation, no public proof of concept, and the issue is not listed in CISA's KEV catalog.
What to do: Upgrade Curiosity Workspace to the latest vendor-supplied release and consult the vendor advisory for the specific fixed version, since none is stated in the data currently available. Audit existing access groups for memberships or administrator additions that occurred without a corresponding invitation or approval, and remove any unauthorized entries. Until patched, restrict which accounts hold non-guest status and monitor group-enrollment activity for anomalous self-joins.
| Curiosity Workspace | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An authenticated, non-guest user of Curiosity Workspace could enroll themselves as an administrator and member of an existing access group without an invitation or approval. It did not grant application-wide administrator privileges, and the vulnerability could not be used to obtain root access to the application or its underlying host.
- Weakness
- CWE-269, CWE-284
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.