CVE-2026-91081: Suitenumerique Docs
Medium severity, CVSS 5.8. EPSS: 0.4% chance of exploitation in the next 30 days.
Docs through 5.6.1 contains a server-side request forgery vulnerability in the cors-proxy endpoint that allows anonymous attackers to make outbound requests by providing a public document UUID. Attackers can exploit DNS time-of-check-time-of-use race conditions and shared address space bypasses to access internal network resources and exfiltrate image content.
Affected products
- Suitenumerique Docs: up to and including 5.6.1
Published 2026-09-14. Last modified 2026-09-23.