CVE-2026-88817

8.7

Curiosity · Curiosity Workspace

An authenticated user in Curiosity Workspace can perform an unauthorized privilege escalation to become an administrator of an existing access group.

Executive summary

A critical privilege management vulnerability in Curiosity Workspace allows authenticated users to bypass access controls and enroll themselves as group administrators without authorization.

Vulnerability

This flaw is an improper privilege management issue (CWE-269) where an authenticated, non-guest user can self-enroll as an administrator of an existing access group. The vulnerability requires a valid, authenticated user account to execute the unauthorized privilege escalation.

Business impact

The ability for standard users to grant themselves administrative rights over specific access groups creates a significant risk of unauthorized data access and modification within those groups. While the flaw does not grant application-wide administrator privileges or root access to the underlying host, the CVSS score of 8.7 reflects the high risk of internal privilege escalation. Successful exploitation could lead to sensitive information disclosure or the unauthorized alteration of group-specific resources.

Remediation

Immediate Action: Update Curiosity Workspace to version 26.8.70363 or later to apply the necessary security patch.

Proactive Monitoring: Review access control lists and audit logs for unexpected changes in group membership or administrative assignments.

Compensating Controls: Ensure that user permissions are strictly audited and limit access to the workspace for non-essential accounts until the update is deployed.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high CVSS score and the direct impact on internal access control integrity, this vulnerability should be prioritized for remediation. Administrators must verify their current version and apply the update to 26.8.70363 immediately to prevent potential privilege escalation by malicious or compromised internal accounts.

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources

Originally found and disclosed by DELANNOY Marc-Antoine [Airbus Protect] - <vuln@airbus.com>, per the CVE Program record.