CVE-2026-88817 — Privilege escalation via legacy access group creation endpoint
8.7 High CVSS v4.0 Fixed in 26.8.70363
| Field | Value |
|---|---|
| Advisory | CVE-2026-88817 |
| Vendor | Curiosity GmbH |
| Product | Curiosity Studio |
| Severity | 8.7 High (CVSS v4.0) |
| Affected | 26.8.70362 and earlier |
| Fixed in | 26.8.70363 and later (curiosityai/curiosity:70363) |
| Classification | CWE-269 (Improper Privilege Management) · CWE-284 (Improper Access Control) |
| Action | Upgrade |
| Published | 2026-09-10 |
Required action
Upgrade to 26.8.70363 or later. No configuration change or data migration is required.
Summary
An authenticated, non-guest user of Curiosity Studio could enroll themselves as an administrator and member of an existing access group without an invitation or approval.
It did not grant application-wide administrator privileges, and the vulnerability could not be used to obtain root access to the application or its underlying host.
Impact
Access group membership grants visibility of the content a group owns, and of anything else restricted to that group. Access group administrators can change members, roles, and group details, or delete the group.
Vulnerability metrics
| Metric | Value |
|---|---|
| CVSS version | 4.0 |
| Base score | 8.7 High |
| Attack vector | Network |
| Attack complexity | Low |
| Attack requirements | None |
| Privileges required | Low |
| User interaction | None |
| Vulnerable system confidentiality | High |
| Vulnerable system integrity | High |
| Vulnerable system availability | High |
| Subsequent system confidentiality | None |
| Subsequent system integrity | None |
| Subsequent system availability | None |
CVSS vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Recommendations
Upgrade
Move to 26.8.70363 or later. This is the complete fix. See Upgrades and migrations for the upgrade procedure.
Review group membership
After upgrading, review the administrator and member lists for access groups holding sensitive content and remove any unexpected accounts.
Credit
This vulnerability was found and reported by Marc-Antoine Delannoy of the Airbus Protect team — vuln@airbus.com.
Curiosity thanks Airbus Protect for the report and for withholding public disclosure until a fixed build was available.
Questions
Contact your Curiosity support channel and reference this advisory, or write to security@curiosity.ai.
See also
- CVE-2026-88817 on cve.org — the official CVE record.
- Report a Security Issue — how to report a vulnerability to Curiosity.
- Permission model — how access groups govern what a user can see in a workspace.
- Access control model — how a deployment configures those groups.