CVE-2026-88817

Severity CVSS v4.0:
HIGH
Type:
CWE-269 Improper Privilege Management
Publication date:
16/09/2026
Last modified:
23/09/2026

Description

An authenticated, non-guest user of Curiosity Workspace could enroll themselves as an administrator and member of an existing access group without an invitation or approval.<br /> <br /> <br /> <br /> It did not grant application-wide administrator privileges, and the vulnerability could not be used to obtain root access to the application or its underlying host.

References to Advisories, Solutions, and Tools