What is CVE-2026-71234?
CVE-2026-71234 is a critical vulnerability in Documize Community's attachment download route. The Download function in 'domain/attachment/endpoint.go', registered without authentication, accepts a `secure` query parameter and grants access if it's non-empty, enabling unauthorized file access. Updating to the latest version of Documize is recommended to mitigate this issue.
Azərbaycanca: CVE-2026-71234, Documize Community platformasında tapılan kritik bir səhvdir. 'domain/attachment/endpoint.go' faylındakı Download funksiyası əlavə autentifikasiya olmadan qeydiyyatdan keçib və `secure` sorğu parametrini boş olmamaq şərti ilə qəbul edərək istənilən fayla icazəsiz giriş imkanı yaradır. Bu zəiflikdən qorunmaq üçün Documize-i ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
In which function was the CVE-2026-71234 vulnerability found in the Documize platform?
The vulnerability was found in the Download function in the 'domain/attachment/endpoint.go' file.
How can one mitigate the CVE-2026-71234 vulnerability?
Updating Documize to the latest version is recommended to mitigate this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.