← Database

CVE-2026-53620

MEDIUM CVSS: 6.3 Published: 2026-08-31 Modified: 2026-08-31

Description

GROWI contains a vulnerability with an authorization bypass through user-controlled key in the bookmark folder APIs. If this vulnerability is exploited, an authenticated attacker could retrieve, tamper with, and/or delete the other user's bookmark data.

Affected Platforms

Unknown

Weakness Type

CWE-639

References