{"id":"CVE-2026-101004","published":"2026-09-28T06:16:31.570","lastModified":"2026-09-28T15:16:04.793","description":"A security vulnerability has been detected in notionnext-org NotionNext up to 4.10.10. Affected by this issue is the function cleanCache of the file pages/api/cache.js of the component Authentication Guard. The manipulation of the argument token leads to missing authentication. The attack may be initiated remotely. Versions 4.1.0 - 4.9.5.2 allow unauthenticated exploitation due to missing method check. In versions 4.9.5.7 - 4.10.10 a guard present but only enforced when CACHE_REVALIDATION_TOKEN is set. Default deployments remain unprotected. The vendor was contacted early about this disclosure but did not respond in any way.","cvssScore":5.3,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","cwes":["CWE-287","CWE-306"],"vendors":[],"products":[],"references":[{"url":"https://vuldb.com/cve/CVE-2026-101004","tags":[]},{"url":"https://vuldb.com/submit/920379","tags":[]},{"url":"https://vuldb.com/vuln/410874","tags":[]},{"url":"https://vuldb.com/vuln/410874/cti","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}