AUGUST 5, 2026
Live Feed
Back to database
Case File

CVE-2020-26176

MEDIUM · CVSS 4.3 EPSS 0.74%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2020-12-18 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 4.3. See the original NVD description below for full technical details.

CVE
CVE-2020-26176
Severity
MEDIUM
CVSS
4.3
EPSS
0.74%

Original NVD Description

An issue was discovered in tangro Business Workflow before 1.18.1. No (or broken) access control checks exist on the /api/document/<DocumentID>/attachments API endpoint. Knowing a document ID, an attacker can list all the attachments of a workitem, including their respective IDs. This allows the attacker to gather valid attachment IDs for workitems that do not belong to them.

Related CVEs

Other vulnerabilities affecting the same vendor(s)