CVE-2026-88817 — Privilege escalation via legacy access group creation endpoint

8.7 High CVSS v4.0 Fixed in 26.8.70363

Field Value
Advisory CVE-2026-88817
Vendor Curiosity GmbH
Product Curiosity Studio
Severity 8.7 High (CVSS v4.0)
Affected 26.8.70362 and earlier
Fixed in 26.8.70363 and later (curiosityai/curiosity:70363)
Classification CWE-269 (Improper Privilege Management) · CWE-284 (Improper Access Control)
Action Upgrade
Published 2026-09-10
Required action

Upgrade to 26.8.70363 or later. No configuration change or data migration is required.

Summary

An authenticated, non-guest user of Curiosity Studio could enroll themselves as an administrator and member of an existing access group without an invitation or approval.

It did not grant application-wide administrator privileges, and the vulnerability could not be used to obtain root access to the application or its underlying host.

Impact

Access group membership grants visibility of the content a group owns, and of anything else restricted to that group. Access group administrators can change members, roles, and group details, or delete the group.

Vulnerability metrics

Metric Value
CVSS version 4.0
Base score 8.7 High
Attack vector Network
Attack complexity Low
Attack requirements None
Privileges required Low
User interaction None
Vulnerable system confidentiality High
Vulnerable system integrity High
Vulnerable system availability High
Subsequent system confidentiality None
Subsequent system integrity None
Subsequent system availability None

CVSS vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Recommendations

1

Upgrade

Move to 26.8.70363 or later. This is the complete fix. See Upgrades and migrations for the upgrade procedure.

1

Review group membership

After upgrading, review the administrator and member lists for access groups holding sensitive content and remove any unexpected accounts.

Credit

This vulnerability was found and reported by Marc-Antoine Delannoy of the Airbus Protect team — vuln@airbus.com.

Curiosity thanks Airbus Protect for the report and for withholding public disclosure until a fixed build was available.

Questions

Contact your Curiosity support channel and reference this advisory, or write to security@curiosity.ai.

See also

Referenced by

© 2026 Curiosity. All rights reserved.
Powered by Neko