CVE-2026-24901
CVE-2026-24901 is a high-severity vulnerability in Getoutline Outline with a CVSS 3.x base score of 8.1. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-639.
Key facts
- Severity: High (CVSS 3.x base score 8.1)
- EPSS exploit prediction: 0% (24th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2026-12582
- Weakness: CWE-639
- Affected product: Getoutline Outline
- Published:
- Last modified:
Description
Outline is a service that allows for collaborative documentation. Prior to 1.4.0, an Insecure Direct Object Reference (IDOR) vulnerability in the document restoration logic allows any team member to unauthorizedly restore, view, and seize ownership of deleted drafts belonging to other users, including administrators. By bypassing ownership validation during the restore process, an attacker can access sensitive private information and effectively lock the original owner out of their own content. Version 1.4.0 fixes the issue.
Frequently asked questions
- What is CVE-2026-24901?
- Outline is a service that allows for collaborative documentation. Prior to 1.4.0, an Insecure Direct Object Reference (IDOR) vulnerability in the document restoration logic allows any team member to unauthorizedly restore, view, and seize ownership of deleted drafts belonging to other users, including administrators. By bypassing ownership validation during the restore process, an attacker can access sensitive private information and effectively lock the original owner out of their own content. Version 1.4.0 fixes the issue.
- How severe is CVE-2026-24901?
- CVE-2026-24901 has a CVSS 3.x base score of 8.1, rated high severity. It is exploitable over network with low attack complexity, requires low privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability none.
- Is CVE-2026-24901 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (24th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-24901?
- CVE-2026-24901 affects Getoutline Outline. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-24901?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- Does CVE-2026-24901 have an EU (EUVD) identifier?
- Yes. CVE-2026-24901 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2026-12582.
- When was CVE-2026-24901 published?
- CVE-2026-24901 was published on 2026-03-17 and last updated on 2026-06-17.
References
Affected products (1)
- cpe:2.3:a:getoutline:outline:*:*:*:*:*:*:*:*
More vulnerabilities in Getoutline Outline
- CVE-2026-33640 — Critical (CVSS 9.8): Outline is a service that allows for collaborative documentation. Outline implements an Email OTP login flow for users…
- CVE-2024-37829 — High (CVSS 8.8): An issue in Outline <= v0.76.1 allows attackers to execute a session hijacking attack via user interaction with a…
- CVE-2023-54331 — High (CVSS 7.8): Outline 1.6.0 contains an unquoted service path vulnerability that allows local attackers to potentially execute…
- CVE-2026-41649 — High (CVSS 7.7): Outline is a service that allows for collaborative documentation. The `shares.create` API endpoint starting in version…
- CVE-2025-64487 — High (CVSS 7.6): Outline is a service that allows for collaborative documentation. Prior to 1.1.0, a privilege escalation vulnerability…
- CVE-2024-40626 — High (CVSS 7.3): Outline is an open source, collaborative document editor. A type confusion issue was found in ProseMirror’s rendering…
All CVEs affecting Getoutline Outline →
Other CWE-639 (Authorization Bypass Through User-Controlled Key (IDOR)) vulnerabilities
- CVE-2025-40805 — Critical (CVSS 10.0): Affected devices do not properly enforce user authentication on specific API endpoints. This could facilitate an…
- CVE-2024-45032 — Critical (CVSS 10.0): A vulnerability has been identified in Industrial Edge Management Pro (All versions < V1.9.5), Industrial Edge…
- CVE-2026-62283 — Critical (CVSS 9.9): Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Nezha versions 1.14.13…
- CVE-2026-73656 — Critical (CVSS 9.9): Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST…
- CVE-2026-48765 — Critical (CVSS 9.9): TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege read collaborator to extract a…
- CVE-2026-67622 — Critical (CVSS 9.9): Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration…
Browse all CWE-639 (Authorization Bypass Through User-Controlled Key (IDOR)) vulnerabilities →