CVE-2025-64487

Severity CVSS v4.0:
Pending analysis
Type:
CWE-269 Improper Privilege Management
Publication date:
11/02/2026
Last modified:
20/02/2026

Description

Outline is a service that allows for collaborative documentation. Prior to 1.1.0, a privilege escalation vulnerability exists in the Outline document management system due to inconsistent authorization checks between user and group membership management endpoints. This vulnerability is fixed in 1.1.0.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:getoutline:outline:*:*:*:*:*:*:*:* 1.1.0 (excluding)