Link following in Etherpad - CVE-2026-55086

 

Link following in Etherpad - CVE-2026-55086

Published: September 22, 2026


Vulnerability identifier: #VU151594
CSH Severity: Low
CVSS v4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-55086
CWE-ID: CWE-59
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to overwrite files writable by the Etherpad process and disclose limited information.

The vulnerability exists due to insecure temporary file handling in the ImportHandler and ExportHandler when handling import and export operations using a shared temporary directory. A local user can pre-create a symbolic link at a predicted temporary file path and trigger an import or export operation to overwrite files writable by the Etherpad process and disclose limited information.

Exploitation requires predicting a temporary filename, such as by observing an earlier temporary filename.


Affected software

Etherpad

How to mitigate CVE-2026-55086

Install security update from vendor's website.

Etherpad - update to 3.1.0

External References

Related Security Bulletins