
I discovered an IDOR vulnerability in the Outline repository, which has over 38K stars on GitHub. The vulnerability allowed any document to be publicly accessible. It was assigned CVE-2026-41649 and has been published. https://www.cve.org/CVERecord?id=CVE-2026-41649 #cve #bugbounty #infosec #security
Post summary
The author discloses an IDOR vulnerability (CVE-2026-41649) in Outline that lets anyone access any document, without providing a PoC, exploit code, or patch information.
