What is CVE-2026-55089?
CVE-2026-55089 is a critical vulnerability in Etherpad versions from 2.1.0 to 3.1.0 involving improper authorization in the OAuth flow for API requests. The code only checks for the existence of an 'admin' claim rather than validating its authenticity, potentially allowing unauthorized users to gain administrative access. Affected users should apply the latest security patch immediately.
Azərbaycanca: CVE-2026-55089 Etherpad real-time kollaborativ redaktorda 2.1.0-dən 3.1.0-a qədər versiyalarda müşahidə olunan kritik nasazlıqdır. API sorğularının avtorizasiyasında yalnız 'admin' claim-inin mövcudluğu yoxlanılır, onun doğruluğu yoxlanılmır, bu isə səlahiyyəti olmayan istifadəçilərə admin əməliyyatlarına giriş imkanı verə bilər. Təsirə məruz qalan versiyaları istifadə edənlər dərhal təhlükəsizlik yeniləməsini tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-863
FAQ1
What versions of Etherpad are affected by CVE-2026-55089 and what is the root cause?
This critical vulnerability affects Etherpad versions from 2.1.0 to 3.1.0. The root cause is improper authorization in the OAuth flow for API requests, where the code only checks for the existence of an 'admin' claim rather than validating its authenticity.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.