PT-2026-6642 · Collabora+1 · Collabora Online Development Edition+2

Caolanm

·

Publicado

2026-02-05

·

Atualizado

2026-02-06

·

CVE-2026-23623

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Collabora Online versions prior to 23.05.20.1 Collabora Online versions prior to 24.04.17.3 Collabora Online versions prior to 25.04.7.5 Collabora Online Development Edition versions prior to 25.04.08.2
Description Collabora Online is a collaborative online office suite based on LibreOffice technology. A user with view-only rights and no download privileges can obtain a local copy of a shared file. Pressing Ctrl+Shift+S initiates the file download process, bypassing access restrictions and leading to unauthorized data retrieval.
Recommendations Update Collabora Online to version 23.05.20.1 or later. Update Collabora Online to version 24.04.17.3 or later. Update Collabora Online to version 25.04.7.5 or later. Update Collabora Online Development Edition to version 25.04.08.2 or later.

Exploit

Correção

Improper Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-23623
GHSA-68V6-R6QQ-MMQ2

Produtos afetados

Collabora Online
Collabora Online Development Edition
Libreoffice