{"id":"CVE-2026-88817","title":"An authenticated, non-guest user of Curiosity Workspace could enroll themselves as an administrator and member of an existing access group without an invitation or approval.\n\n\n\nIt did not grant application-wide administrator privileges, …","summary":"An authenticated, non-guest user of Curiosity Workspace could enroll themselves as an administrator and member of an existing access group without an invitation or approval.\n\n\n\nIt did not grant application-wide administrator privileges, …","severity":"high","cvss":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","cwe":["CWE-269","CWE-284"],"vendor":"Curiosity GmbH","product":"Curiosity Workspace","affected":["curiosity_workspace 26.8.70362"],"published":"2026-09-16","updated":"2026-09-23","sourceUpdated":"2026-09-23T11:10:00.187","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-88817","references":[{"url":"https://docs.curiosity.ai/security/advisories/cve-2026-88817","label":"cert@airbus.com"}],"tags":["nvd","cve.org"],"epss":0.00351,"epssPercentile":0.25936,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-16T13:11:20.243964Z"},"cvssSource":"cna","ingestedAt":"2026-09-16T12:55:21.864Z","slug":"CVE-2026-88817","body":"## Overview\n\nAn authenticated, non-guest user of Curiosity Workspace could enroll themselves as an administrator and member of an existing access group without an invitation or approval.\n\n\n\nIt did not grant application-wide administrator privileges, and the vulnerability could not be used to obtain root access to the application or its underlying host.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":47.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}