SB2026092231 - Multiple vulnerabilities in Etherpad
Published: September 22, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 4 vulnerabilities.
1) Link following (CVE-ID: CVE-2026-55086)
CWE-ID: CWE-59 - Improper Link Resolution Before File Access ('Link Following')
CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to overwrite files writable by the Etherpad process and disclose limited information.
The vulnerability exists due to insecure temporary file handling in the ImportHandler and ExportHandler when handling import and export operations using a shared temporary directory. A local user can pre-create a symbolic link at a predicted temporary file path and trigger an import or export operation to overwrite files writable by the Etherpad process and disclose limited information.
Exploitation requires predicting a temporary filename, such as by observing an earlier temporary filename.
2) Cross-site scripting (CVE-ID: CVE-2026-55087)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote attacker to execute arbitrary JavaScript in an administrator's browser.
The vulnerability exists due to improper neutralization of input during web page generation in the admin static-serving handler when processing an x-proxy-path header in admin HTML, JavaScript, and CSS assets. A remote attacker can send a request with a crafted x-proxy-path header to execute arbitrary JavaScript in an administrator's browser.
User interaction is required, and cache poisoning requires a shared cache that does not vary cached responses by the x-proxy-path header.
3) Authentication Bypass by Capture-replay (CVE-ID: CVE-2026-55088)
CWE-ID: CWE-294 - Authentication Bypass by Capture-replay
CVSSv4: 7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to impersonate the originating author.
The vulnerability exists due to missing expiration and single-use enforcement in the /tokenTransfer/{uuid} endpoint when redeeming a disclosed token transfer URL. A remote attacker can send a request containing a disclosed transfer UUID to impersonate the originating author.
User interaction is required for a legitimate user to initiate a token transfer and for its UUID to be disclosed.
4) Incorrect authorization (CVE-ID: CVE-2026-55089)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to access all Etherpad HTTP API endpoints with administrator privileges.
The vulnerability exists due to improper authorization in APIHandler when validating JWTs issued through the OAuth authorization_code flow. A remote user can obtain a signed JWT with an admin claim set to false to access all Etherpad HTTP API endpoints with administrator privileges.
Only instances using an authentication method other than apikey and having a settings.users entry with is_admin explicitly set to false are affected.
Remediation
Install update from vendor's website.
References
- https://github.com/ether/etherpad/security/advisories/GHSA-2jwf-f4xq-f24h
- https://github.com/ether/etherpad/commit/8c6104c
- https://github.com/ether/etherpad/security/advisories/GHSA-fjgc-3mj7-8rg8
- https://github.com/ether/etherpad/security/advisories/GHSA-vqfp-p66c-xrp9
- https://github.com/ether/etherpad/commit/41cb680
- https://github.com/ether/etherpad/security/advisories/GHSA-qfmh-fph3-mw8q
- https://github.com/ether/etherpad/commit/63e9b2d