CVE-2020-26176: Tangro Business Workflow

Medium severity, CVSS 4.3. EPSS: 0.8% chance of exploitation in the next 30 days.

An issue was discovered in tangro Business Workflow before 1.18.1. No (or broken) access control checks exist on the /api/document/<DocumentID>/attachments API endpoint. Knowing a document ID, an attacker can list all the attachments of a workitem, including their respective IDs. This allows the attacker to gather valid attachment IDs for workitems that do not belong to them.

Affected products

  • Tangro Business Workflow: before 1.18.1 (fixed in 1.18.1)

Published 2020-12-18. Last modified 2026-06-17.