Incorrect authorization in Etherpad - CVE-2026-55089
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote user to access all Etherpad HTTP API endpoints with administrator privileges.
The vulnerability exists due to improper authorization in APIHandler when validating JWTs issued through the OAuth authorization_code flow. A remote user can obtain a signed JWT with an admin claim set to false to access all Etherpad HTTP API endpoints with administrator privileges.
Only instances using an authentication method other than apikey and having a settings.users entry with is_admin explicitly set to false are affected.