{"id":"CVE-2026-88817","published":"2026-09-16T13:18:07.837","lastModified":"2026-09-18T17:47:52.827","description":"An authenticated, non-guest user of Curiosity Workspace could enroll themselves as an administrator and member of an existing access group without an invitation or approval.\n\n\n\nIt did not grant application-wide administrator privileges, and the vulnerability could not be used to obtain root access to the application or its underlying host.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-269","CWE-284"],"vendors":[],"products":[],"references":[{"url":"https://docs.curiosity.ai/security/advisories/cve-2026-88817","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}