Description
An authenticated, non-guest user of Curiosity Workspace could enroll themselves as an administrator and member of an existing access group without an invitation or approval.
It did not grant application-wide administrator privileges, and the vulnerability could not be used to obtain root access to the application or its underlying host.
It did not grant application-wide administrator privileges, and the vulnerability could not be used to obtain root access to the application or its underlying host.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
The following updates will fix this vulnerability: * Curiosity Workplace =>26.8.70363
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://docs.curiosity.ai/security/advisories/cve-2026-88817 |
|
History
Wed, 16 Sep 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authenticated, non-guest user of Curiosity Workspace could enroll themselves as an administrator and member of an existing access group without an invitation or approval. It did not grant application-wide administrator privileges, and the vulnerability could not be used to obtain root access to the application or its underlying host. | |
| Title | Privilege escalation via legacy access group creation endpoint | |
| Weaknesses | CWE-269 CWE-284 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: airbus
Published:
Updated: 2026-09-16T13:13:51.032Z
Reserved: 2026-09-10T08:48:49.299Z
Link: CVE-2026-88817
No data.
Status : Received
Published: 2026-09-16T13:18:07.837
Modified: 2026-09-16T13:18:07.837
Link: CVE-2026-88817
No data.
OpenCVE Enrichment
No data.