CVE-2026-33640Disclosure(getoutline / outline)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch getoutline outline systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Outline is a service that allows for collaborative documentation. Outline implements an Email OTP login flow for users not associated with an Identity Provider. Starting in version 0.86.0 and prior to version 1.6.0, Outline does not invalidate OTP codes based on amount or frequency of invalid submissions, rather it relies on the rate limiter to restrict attempts. Consequently, identified bypasses in the rate limiter permit unrestricted OTP code submissions within the codes lifetime. This allows attackers to perform brute force attacks which enable account takeover. Version 1.6.0 fixes the issue.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-307

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • outline

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-26); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
outline

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-26: 2Mentions · 2026-03-27: 1PoC Mentioned / Linked · 2026-03-27: 1Patch / Workaround · 2026-03-27: 1Technical Details · 2026-03-26: 1Technical Details · 2026-03-27: 103-2603-27
Signal classification3 categories
Disclosure
133.3%
General
133.3%
PoC
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-262
Disclosure1General1
2026-03-271
PoC1
Full discourse3 posts
  • CCB Alert@CCBalert
    PoC

    Warning: #OTP codes generated in #Outline are susceptible to #bruteforce attacks as no amount or frequency limitation of invalid attempts is implemented. A #PoC is available for the critical #CVE-2026-33640, exploitation can lead to account compromise. #Patch #Patch #Patch

    Post summary

    OTP codes in Outline are vulnerable to brute‑force attacks; a PoC for CVE‑2026‑33640 exists that can compromise accounts, and a patch is recommended.

    01000247
    7.2K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-33640 Outline is a service that allows for collaborative documentation. Outline implements an Email OTP login flow for users not associated with an Identity Provider. Start… https://www.cve.org/CVERecord?id=CVE-2026-33640

    Post summary

    The snippet merely references a CVE record for Outline’s Email OTP flow without providing details on exploitation, mitigation, or technical specifics.

    0000062
    56.9K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-33640: Outline has a rate limit bypass ... Rate limiter bypass + infinite OTP attempts = trivial account takeover against any Outline instance running 0.86.0-1.5.... https://zerodaysignal.com/vulnerability/CVE-2026-33640 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post reveals a rate‑limiter bypass in Outline 0.86.0‑1.5 that enables infinite OTP attempts, making account takeover trivial for affected versions.

    0000059
    194 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgetoutlineoutline---

Explore more