{"id":"CVE-2026-93547","title":"A missing authorization check in the Vaadin Spreadsheet component allows an authenticated user of an application that renders a spreadsheet to add or replace cell comments on a sheet that has protection enabled, including on cells that a…","summary":"A missing authorization check in the Vaadin Spreadsheet component allows an authenticated user of an application that renders a spreadsheet to add or replace cell comments on a sheet that has protection enabled, including on cells that a…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","cwe":["CWE-285"],"vendor":"vaadin","product":"com.vaadin:vaadin","affected":["com.vaadin:vaadin >= 23.1.0 < 23.6.14","com.vaadin:vaadin >= 24.0.0 < 24.9.22","com.vaadin:vaadin >= 24.10.0 < 24.10.10","com.vaadin:vaadin >= 25.0.0 < 25.1.12","com.vaadin:vaadin >= 25.2.0 < 25.2.7","com.vaadin:vaadin-spreadsheet-flow >= 23.1.0 < 23.6.14","com.vaadin:vaadin-spreadsheet-flow >= 24.0.0 < 24.9.22","com.vaadin:vaadin-spreadsheet-flow >= 24.10.0 < 24.10.10","com.vaadin:vaadin-spreadsheet-flow >= 25.0.0 < 25.1.12","com.vaadin:vaadin-spreadsheet-flow >= 25.2.0 < 25.2.7","com.vaadin:vaadin-spreadsheet >= 2.0.0 < 3.1.1"],"published":"2026-09-30","updated":"2026-09-30","sourceUpdated":"2026-09-30T15:22:36.723","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-93547","references":[{"url":"https://github.com/vaadin/flow-components/pull/9905","label":"security@vaadin.com"},{"url":"https://github.com/vaadin/flow-components/pull/9907","label":"security@vaadin.com"},{"url":"https://github.com/vaadin/flow-components/pull/9908","label":"security@vaadin.com"},{"url":"https://github.com/vaadin/flow-components/pull/9909","label":"security@vaadin.com"},{"url":"https://github.com/vaadin/flow-components/pull/9910","label":"security@vaadin.com"},{"url":"https://github.com/vaadin/flow-components/pull/9956","label":"security@vaadin.com"},{"url":"https://github.com/vaadin/spreadsheet/pull/866","label":"security@vaadin.com"},{"url":"https://vaadin.com/security/cve-2026-93547","label":"security@vaadin.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-30T14:25:51.477902Z"},"cvssSource":"cna","ingestedAt":"2026-09-30T14:05:17.368Z","slug":"CVE-2026-93547","body":"## Overview\n\nA missing authorization check in the Vaadin Spreadsheet component allows an authenticated user of an application that renders a spreadsheet to add or replace cell comments on a sheet that has protection enabled, including on cells that are locked. Writing a comment to a cell that does not exist yet also creates the row and the cell.\n\n\nUsers of affected versions should apply the following mitigation or upgrade. Releases that have fixed this issue include:\n\nProduct version\nVaadin 23.1.0 - 23.6.13\nVaadin 24.0.0 - 24.9.21\nVaadin 24.10.0 - 24.10.9\nVaadin 25.0.0 - 25.1.11\nVaadin 25.2.0 - 25.2.6\nVaadin Framework 7 and 8 with the Spreadsheet add-on 2.0.0 - 3.1.0\n\nMitigation\nUpgrade to 23.6.14\nUpgrade to 24.9.22\nUpgrade to 24.10.10\nUpgrade to 25.1.12\nUpgrade to 25.2.7 or newer\nUpgrade the Spreadsheet add-on to 3.1.1\n\nPlease note that Vaadin versions 10-13 and 15-22 are no longer supported and you should update either to the latest 23, 24, 25 version.\n\nArtifacts\nMaven coordinates Vulnerable versions Fixed version\ncom.vaadin:vaadin 23.1.0 - 23.6.13 >=23.6.14\ncom.vaadin:vaadin 24.0.0 - 24.9.21 >=24.9.22\ncom.vaadin:vaadin 24.10.0 - 24.10.9 >=24.10.10\ncom.vaadin:vaadin 25.0.0 - 25.1.11 >=25.1.12\ncom.vaadin:vaadin 25.2.0 - 25.2.6 >=25.2.7\ncom.vaadin:vaadin-spreadsheet-flow 23.1.0 - 23.6.13 >=23.6.14\ncom.vaadin:vaadin-spreadsheet-flow 24.0.0 - 24.9.21 >=24.9.22\ncom.vaadin:vaadin-spreadsheet-flow 24.10.0 - 24.10.9 >=24.10.10\ncom.vaadin:vaadin-spreadsheet-flow 25.0.0 - 25.1.11 >=25.1.12\ncom.vaadin:vaadin-spreadsheet-flow 25.2.0 - 25.2.6 >=25.2.7\ncom.vaadin:vaadin-spreadsheet 2.0.0 - 3.1.0 >=3.1.1\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}