CVE-2026-68951

GROWI contains an incorrect authorization vulnerability. If this vulnerability is exploited, an unauthenticated attacker could retrieve the other user's bookmark data.

  • Published Aug 31, 2026
  • CVSS 6.9 medium
  • 0.3% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-68951 at the National Vulnerability Database