CVE-2026-24901Disclosure(getoutline / outline)

LOWCVSS 8.8 · HIGH

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Outline is a service that allows for collaborative documentation. Prior to 1.4.0, an Insecure Direct Object Reference (IDOR) vulnerability in the document restoration logic allows any team member to unauthorizedly restore, view, and seize ownership of deleted drafts belonging to other users, including administrators. By bypassing ownership validation during the restore process, an attacker can access sensitive private information and effectively lock the original owner out of their own content. Version 1.4.0 fixes the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • outline

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • 4 total mentions across 1 day

Affected systems

Vendors
Products
outline

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-03-17: 4Technical Details · 2026-03-17: 403-17
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Full discourse4 posts
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-24901 - High Outline is a service that allows for collaborative documentation. Prior to 1.4.0, an Insecure Direct Object Reference (IDOR) vulnerability in the document restoration logic allows any team me... https://www.thehackerwire.com/vulnerability/CVE-2026-24901/ https://t.co/8Rm47PWkzn

    Post summary

    The tweet announces CVE-2026-24901 as an IDOR flaw in Outline’s document restoration logic affecting versions before 1.4.0, without mentioning PoC, exploitation, or remediation.

    0000045
    138 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-24901 Outline is a service that allows for collaborative documentation. Prior to 1.4.0, an Insecure Direct Object Reference (IDOR) vulnerability in the document restoration… https://www.cve.org/CVERecord?id=CVE-2026-24901

    Post summary

    CVE-2026-24901 is an IDOR vulnerability in Outline affecting versions prior to 1.4.0, with no PoC, exploit tool, active exploitation, or patch information mentioned.

    00000119
    56.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-24901 Insecure Direct Object Reference Vulnerability in Outline Before 1.4.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-24901

    Post summary

    A new IDOR vulnerability (CVE-2026-24901) affecting Outline versions prior to 1.4.0 has been reported.

    0000046
    4.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-24901 - Outline's IDOR allows unauthorized viewing and seizing of private deleted drafts Intel Report: https://ift.tt/McLkga0

    Post summary

    The text announces CVE-2026-24901 as an IDOR flaw in Outline allowing unauthorized access to deleted drafts, accompanied by an intel report link.

    0000036
    336 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgetoutlineoutline---

Explore more