CVE-2026-88817
Severity CVSS v4.0:
HIGH
Type:
CWE-269
Improper Privilege Management
Publication date:
16/09/2026
Last modified:
23/09/2026
Description
An authenticated, non-guest user of Curiosity Workspace could enroll themselves as an administrator and member of an existing access group without an invitation or approval.<br />
<br />
<br />
<br />
It did not grant application-wide administrator privileges, and the vulnerability could not be used to obtain root access to the application or its underlying host.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH


