Description
An authenticated, non-guest user of Curiosity Workspace could enroll themselves as an administrator and member of an existing access group without an invitation or approval.



It did not grant application-wide administrator privileges, and the vulnerability could not be used to obtain root access to the application or its underlying host.
Published: 2026-09-16
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

The following updates will fix this vulnerability: * Curiosity Workplace =>26.8.70363

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Curiosity
Curiosity curiosity Workspace
Vendors & Products Curiosity
Curiosity curiosity Workspace

Wed, 16 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Description An authenticated, non-guest user of Curiosity Workspace could enroll themselves as an administrator and member of an existing access group without an invitation or approval. It did not grant application-wide administrator privileges, and the vulnerability could not be used to obtain root access to the application or its underlying host.
Title Privilege escalation via legacy access group creation endpoint
Weaknesses CWE-269
CWE-284
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Curiosity Curiosity Workspace
cve-icon MITRE

Status: PUBLISHED

Assigner: airbus

Published:

Updated: 2026-09-16T13:13:51.032Z

Reserved: 2026-09-10T08:48:49.299Z

Link: CVE-2026-88817

cve-icon Vulnrichment

Updated: 2026-09-16T13:11:24.769Z

cve-icon NVD

Status : Received

Published: 2026-09-16T13:18:07.837

Modified: 2026-09-16T14:17:12.520

Link: CVE-2026-88817

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T19:50:13Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-284

    Improper Access Control