{"id":"CVE-2026-108110","title":"MOVO through 0.2.3 contains an authorization bypass vulnerability in the chat-api document endpoints that allows authenticated users to access other users' stored objects by supplying arbitrary object paths","summary":"MOVO through 0.2.3 contains an authorization bypass vulnerability in the chat-api document endpoints that allows authenticated users to access other users' stored objects by supplying arbitrary object paths. Attackers who know a target's…","severity":"medium","cvss":6.8,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","cwe":["CWE-639"],"published":"2026-10-09","updated":"2026-10-09","sourceUpdated":"2026-10-09T17:07:31.693","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-108110","references":[{"url":"https://github.com/himovo/movo","label":"disclosure@vulncheck.com"},{"url":"https://github.com/himovo/movo/blob/v0.2.3/services/chat-api/app/api/endpoints/documents.py#L237-L274","label":"disclosure@vulncheck.com"},{"url":"https://github.com/himovo/movo/blob/v0.2.3/services/chat-api/app/api/endpoints/documents.py#L91-L109","label":"disclosure@vulncheck.com"},{"url":"https://hackmd.io/HfAnJ59RQuSNLYmNGkAKog","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/movo-through-0.2.3-authorization-bypass-via-document-endpoints","label":"disclosure@vulncheck.com"}],"tags":["nvd"],"ingestedAt":"2026-10-09T17:04:42.810Z","slug":"CVE-2026-108110","body":"## Overview\n\nMOVO through 0.2.3 contains an authorization bypass vulnerability in the chat-api document endpoints that allows authenticated users to access other users' stored objects by supplying arbitrary object paths. Attackers who know a target's object path can send it to /api/documents/fetch or /api/documents/save-blueprint to read private documents and overwrite presentation blueprints.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":37,"depthScoreParts":{"impact":37.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}