CRITICAL
9.9 CVE-2026-55089 Published 19 Aug 2026
Etherpad OAuth Admin Privilege Escalation
Worried this affects one of your servers?
Etherpad, a real-time collaborative editor, had a vulnerability in its OAuth authorization process.
Etherpad versions 2.1.0 to 3.1.0 incorrectly authorized requests to /api/2/* in the authorization_code OAuth path, allowing non-admin users with valid signed tokens to invoke administrative functions.
- This could lead to disclosure, modification, or deletion of pads across the instance.
This issue is fixed in version 3.1.0.
Reference: CVE-2026-55089 on NVD
← Back to Security News