What is CVE-2026-55088?
CVE-2026-55088 is a vulnerability in Etherpad's token transfer mechanism. An author token created via the POST /tokenTransfer endpoint can be exposed through GET /tokenTransfer/{uuid} in versions 2.6.0 to 3.1.0. Users should upgrade Etherpad to the latest version to mitigate the issue.
Azərbaycanca: CVE-2026-55088 Etherpad real-vaxt əməkdaşlıq redaktorunda token ötürülməsi mexanizmində zəiflikdir. 2.6.0 ilə 3.1.0 versiyaları arasında POST /tokenTransfer endpointi ilə yaradılan author token-i, GET /tokenTransfer/{uuid} vasitəsilə əlçatan olur. Təsirə məruz qalmamaq üçün Etherpad-i ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Which Etherpad versions are affected by CVE-2026-55088?
CVE-2026-55088 affects Etherpad versions 2.6.0 to 3.1.0.
Through which endpoint can CVE-2026-55088 be exploited?
The vulnerability allows exposure of the author token via the GET /tokenTransfer/{uuid} endpoint.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.