Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 06 Feb 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 06 Feb 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Collaboraoffice
Collaboraoffice online |
|
| Vendors & Products |
Collaboraoffice
Collaboraoffice online |
Thu, 05 Feb 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Collabora Online is a collaborative online office suite based on LibreOffice technology. Prior to Collabora Online Development Edition version 25.04.08.2 and prior to Collabora Online versions 23.05.20.1, 24.04.17.3, and 25.04.7.5, a user with view-only rights and no download privileges can obtain a local copy of a shared file. Although there are no corresponding buttons in the interface, pressing Ctrl+Shift+S initiates the file download process. This allows the user to bypass the access restrictions and leads to unauthorized data retrieval. This issue has been patched in Collabora Online Development Edition version 25.04.08.2 and Collabora Online versions 23.05.20.1, 24.04.17.3, and 25.04.7.5. | |
| Title | Collabora Online vulnerable to Authorization Bypass | |
| Weaknesses | CWE-285 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-06T19:28:38.548Z
Reserved: 2026-01-14T16:08:37.482Z
Link: CVE-2026-23623
Updated: 2026-02-06T19:28:35.393Z
Status : Awaiting Analysis
Published: 2026-02-06T00:15:56.663
Modified: 2026-02-06T15:14:47.703
Link: CVE-2026-23623
No data.
OpenCVE Enrichment
Updated: 2026-02-06T12:05:02Z