vulnti.work

Docs before 5.4.1 fails to properly revoke websocket collaboration connections when access is revoked at parent documents. Attackers with revoked access can retain real-time read and write access to …

Medium CVSS 6.8
CVECVE-2026-92800
First seen2026-09-19 03:16 UTC
Disclosed2026-09-16 21:17 UTC
Last updated2026-09-19 03:16 UTC
Channel statusauto

Summary

Docs before 5.4.1 fails to properly revoke websocket collaboration connections when access is revoked at parent documents. Attackers with revoked access can retain real-time read and write access to sub-documents through open websocket sessions that are never disconnected.

In-depth triage

No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).

Sources

  • NVD DATABASE

Original Links

Timeline

  1. nvd_ingest NVD