CRITICAL 9.9 CVE-2026-55089 Published 19 Aug 2026

Etherpad OAuth Admin Privilege Escalation

Worried this affects one of your servers?

Etherpad, a real-time collaborative editor, had a vulnerability in its OAuth authorization process.

Etherpad versions 2.1.0 to 3.1.0 incorrectly authorized requests to /api/2/* in the authorization_code OAuth path, allowing non-admin users with valid signed tokens to invoke administrative functions.

  • This could lead to disclosure, modification, or deletion of pads across the instance.

This issue is fixed in version 3.1.0.

Reference: CVE-2026-55089 on NVD

← Back to Security News