CVE-2026-92800

Source
https://cve.org/CVERecord?id=CVE-2026-92800
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92800.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-92800
Published
2026-09-16T20:32:51Z
Modified
2026-09-20T11:30:56Z
Severity
  • 7.6 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Docs before 5.4.1 Stale Collaboration Session After Access Revocation
Details

Docs before 5.4.1 fails to properly revoke websocket collaboration connections when access is revoked at parent documents. Attackers with revoked access can retain real-time read and write access to sub-documents through open websocket sessions that are never disconnected.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-613"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92800.json"
}
References

Affected packages

Git / github.com/suitenumerique/docs

Affected ranges

Type
GIT
Repo
https://github.com/suitenumerique/docs
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "5.4.1"
        }
    ],
    "source": [
        "DESCRIPTION",
        "REFERENCES"
    ]
}

Affected versions

Other
production
v.*
v.3.4.2
v0.*
v0.1.0
v1.*
v1.0.0
v1.10.0
v1.2.0
v1.2.1
v1.3.0
v1.4.0
v1.5.0
v1.5.1
v1.5.1-preprod
v1.6.0
v1.7.0
v1.8.0
v1.8.1
v1.8.2
v1.9.0
v2.*
v2.0.0
v2.0.1
v2.1.0
v2.2.0
v2.3.0
v2.4.0
v2.5.0
v2.6.0
v3.*
v3.0.0
v3.1.0
v3.10.0
v3.10.0-preprod
v3.2.0
v3.2.0-preprod
v3.2.1
v3.3.0
v3.3.0-preprod
v3.4.0
v3.4.1
v3.4.1-preprod
v3.4.2
v3.4.2-preprod
v3.5.0
v3.5.0-preprod
v3.6.0
v3.7.0
v3.7.0-preprod
v3.8.0
v3.8.0-preprod
v3.8.1
v3.8.1-preprod
v3.8.2
v3.8.2-preprod
v3.9.0
v3.9.0-preprod
v4.*
v4.0.0
v4.0.0-preprod
v4.1.0
v4.1.0-preprod
v4.2.0
v4.2.0-preprod
v4.3.0
v4.3.0-preprod
v4.4.0
v4.4.0-preprod
v4.5.0
v4.5.0-preprod
v4.6.0
v4.7.0
v4.7.0-preprod
v4.8.0
v4.8.0-preprod
v4.8.0-psycopgpool
v4.8.1
v4.8.1-preprod
v4.8.2
v4.8.2-preprod
v4.8.3
v4.8.4
v4.8.4-preprod
v4.8.5
v4.8.5-preprod
v4.8.6
v5.*
v5.1.0
v5.2.0
v5.2.0-preprod
v5.2.1
v5.2.1-preprod
v5.3.0
v5.3.0-preprod
v5.4.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92800.json"