Description
An authenticated, non-guest user of Curiosity Workspace could enroll themselves as an administrator and member of an existing access group without an invitation or approval.



It did not grant application-wide administrator privileges, and the vulnerability could not be used to obtain root access to the application or its underlying host.
Published: 2026-09-16
Score: 8.7 High
EPSS: n/a
KEV: No
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

The following updates will fix this vulnerability: * Curiosity Workplace =>26.8.70363

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Description An authenticated, non-guest user of Curiosity Workspace could enroll themselves as an administrator and member of an existing access group without an invitation or approval. It did not grant application-wide administrator privileges, and the vulnerability could not be used to obtain root access to the application or its underlying host.
Title Privilege escalation via legacy access group creation endpoint
Weaknesses CWE-269
CWE-284
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: airbus

Published:

Updated: 2026-09-16T13:13:51.032Z

Reserved: 2026-09-10T08:48:49.299Z

Link: CVE-2026-88817

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T13:18:07.837

Modified: 2026-09-16T13:18:07.837

Link: CVE-2026-88817

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses