Authentication Bypass by Capture-replay in Etherpad - CVE-2026-55088
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote attacker to impersonate the originating author.
The vulnerability exists due to missing expiration and single-use enforcement in the /tokenTransfer/{uuid} endpoint when redeeming a disclosed token transfer URL. A remote attacker can send a request containing a disclosed transfer UUID to impersonate the originating author.
User interaction is required for a legitimate user to initiate a token transfer and for its UUID to be disclosed.