{"id":"CVE-2026-33146","summary":"Docmost's Public Share Search Exposes Metadata of Restricted Children","details":"Docmost is open-source collaborative wiki and documentation software. An authorization bypass vulnerability in versions 0.70.0 through 0.70.2 exposes restricted child page titles and text snippets through the public search endpoint (`POST /api/search/share-search`) for publicly shared content. This flaw allows unauthenticated users to enumerate and retrieve content that should remain hidden from public share viewers, leading to a confidentiality breach. Version 0.70.3 contains a patch.","aliases":["GHSA-qq4c-8rjr-w42c"],"modified":"2026-07-15T01:49:11.412061554Z","published":"2026-04-14T21:36:53.562Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/33xxx/CVE-2026-33146.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-285"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/33xxx/CVE-2026-33146.json"},{"type":"ADVISORY","url":"https://github.com/docmost/docmost/security/advisories/GHSA-qq4c-8rjr-w42c"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33146"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/docmost/docmost","events":[{"introduced":"37355452e11958bcd98c1588fe3ece227e983e46"},{"fixed":"cc5c8002382cf7deb46eebae5d73194e6148914c"}],"database_specific":{"cpe":"cpe:2.3:a:docmost:docmost:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0.70.0"},{"fixed":"0.70.3"}],"source":["AFFECTED_FIELD","CPE_RANGE"]}}],"versions":["v0.70.2","v0.70.1","v0.70.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-33146.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"}]}