
CVE-2026-28374 Editors could delete any annotation, even those they do not have read access to. The editor user cannot create or read the annotations. https://www.cve.org/CVERecord?id=CVE-2026-28374
Post summary
The post reports a CVE exposing a privilege issue where editors can delete annotations they shouldn’t have permission to modify.
