CVE-2026-7702

A vulnerability was detected in toeverything AFFiNE up to 0.26.3. This issue affects the function allowDocPreview of the file /workspace/:workspaceId/:docId of the component Public Markdown Preview Endpoint. The manipulation results in authorization bypass. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Configurations

No configuration.

History

03 May 2026, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-03 16:15

Updated : 2026-05-05 19:11


NVD link : CVE-2026-7702

Mitre link : CVE-2026-7702

CVE.ORG link : CVE-2026-7702


JSON object : View

Products Affected

No product.

CWE
CWE-285

Improper Authorization

CWE-639

Authorization Bypass Through User-Controlled Key