CVE Explorer
CVE-2026-27579
CollabPlatform is a full-stack, real-time doc collaboration platform. In all versions of CollabPlatform, the Appwrite project used by the application is misconfigured to allow arbitrary origins in CORS responses while also permitting credentialed requests. An attacker-controlled domain can issue authenticated cross-origin requests and read sensitive user account information, including email address, account identifiers, and MFA status. The issue did not have a fix at the time of publication.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-346","description":"CWE-346: Origin Validation Error","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:0de8ce88655e8900ca7de152dd5859ded2dcc1b1b411a1bfdf63fa729f2c9a9f · sha256:f5f369b6468a020e… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-942","description":"CWE-942: Permissive Cross-domain Policy with Untrusted Domains","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:0de8ce88655e8900ca7de152dd5859ded2dcc1b1b411a1bfdf63fa729f2c9a9f · sha256:f5f369b6468a020e… · /containers/cna/problemTypes/1/descriptions/0
Affected products and versions
1 source assertion{"product":"realtime-collaboration-platform","vendor":"karnop","versions":[{"status":"affected","version":"<= master"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:0de8ce88655e8900ca7de152dd5859ded2dcc1b1b411a1bfdf63fa729f2c9a9f · sha256:f5f369b6468a020e… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":7.4,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:0de8ce88655e8900ca7de152dd5859ded2dcc1b1b411a1bfdf63fa729f2c9a9f · sha256:f5f369b6468a020e… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
2 source assertions{"cweId":"CWE-346","description":"CWE-346: Origin Validation Error","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:0de8ce88655e8900ca7de152dd5859ded2dcc1b1b411a1bfdf63fa729f2c9a9f · sha256:f5f369b6468a020e… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-942","description":"CWE-942: Permissive Cross-domain Policy with Untrusted Domains","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:0de8ce88655e8900ca7de152dd5859ded2dcc1b1b411a1bfdf63fa729f2c9a9f · sha256:f5f369b6468a020e… · /containers/cna/problemTypes/1/descriptions/0
Source references
1 source assertion{"name":"https://github.com/karnop/realtime-collaboration-platform/security/advisories/GHSA-qh5m-p8jh-hx88","tags":["x_refsource_CONFIRM"],"url":"https://github.com/karnop/realtime-collaboration-platform/security/advisories/GHSA-qh5m-p8jh-hx88"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:0de8ce88655e8900ca7de152dd5859ded2dcc1b1b411a1bfdf63fa729f2c9a9f · sha256:f5f369b6468a020e… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.