CVE-2026-88817: Curiosity GmbH Curiosity Workspace
High severity, CVSS 8.7. EPSS: 0.4% chance of exploitation in the next 30 days.
An authenticated, non-guest user of Curiosity Workspace could enroll themselves as an administrator and member of an existing access group without an invitation or approval. It did not grant application-wide administrator privileges, and the vulnerability could not be used to obtain root access to the application or its underlying host.
Affected products
- Curiosity GmbH Curiosity Workspace: version 26.8.70362 only
Published 2026-09-16. Last modified 2026-09-23.