CollabPlatform is a full-stack, real-time doc collaboration platform. In all versions of CollabPlatform, the Appwrite project used by the application is misconfigured to allow arbitrary origins in CORS responses while also permitting credentialed requests. An attacker-controlled domain can issue authenticated cross-origin requests and read sensitive user account information, including email address, account identifiers, and MFA status. The issue did not have a fix at the time of publication.
History

Sat, 21 Feb 2026 10:30:00 +0000

Type Values Removed Values Added
Description CollabPlatform is a full-stack, real-time doc collaboration platform. In all versions of CollabPlatform, the Appwrite project used by the application is misconfigured to allow arbitrary origins in CORS responses while also permitting credentialed requests. An attacker-controlled domain can issue authenticated cross-origin requests and read sensitive user account information, including email address, account identifiers, and MFA status. The issue did not have a fix at the time of publication.
Title CollabPlatform : CORS Misconfiguration Allows Arbitrary Origin With Credentials Leading to Authenticated Account Data Exposure
Weaknesses CWE-346
CWE-942
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-02-21T10:22:15.671Z

Reserved: 2026-02-20T17:40:28.449Z

Link: CVE-2026-27579

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-02-21T11:15:57.600

Modified: 2026-02-21T11:15:57.600

Link: CVE-2026-27579

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.