216.73.217.22

CVE-2026-27579

· Published 21/02/2026 11:15 · Modified 21/02/2026 11:15

Labels: CVE-2026-27579 2026-02-21CVE-2026-27579CWE-346[email protected]

Essential information

Published
21/02/2026 11:15
Modified
21/02/2026 11:15
Author
Creator
CVSS
7.4 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N

CVSS metrics

Description

CollabPlatform is a full-stack, real-time doc collaboration platform. In all versions of CollabPlatform, the Appwrite project used by the application is misconfigured to allow arbitrary origins in CORS responses while also permitting credentialed requests. An attacker-controlled domain can issue authenticated cross-origin requests and read sensitive user account information, including email address, account identifiers, and MFA status. The issue did not have a fix at the time of publication.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
collabplatform / collabplatform cpe:2.3:a:collabplatform:collabplatform:*:*:*:*:*:*:*:*
appwrite / appwrite cpe:2.3:a:appwrite:appwrite:*:*:*:*:*:*:*:*

References