CVE-2026-68951: Growi, Inc Growi

Medium severity, CVSS 6.9. EPSS: 0.3% chance of exploitation in the next 30 days.

GROWI contains an incorrect authorization vulnerability. If this vulnerability is exploited, an unauthenticated attacker could retrieve the other user's bookmark data.

Affected products

Published 2026-08-31. Last modified 2026-08-31.