PatchSiren cyber security CVE debrief
CVE-2026-92800 suitenumerique CVE debrief
CVE-2026-92800 debrief: Docs before 5.4.1 retains websocket collaboration connections after access revocation, allowing attackers with revoked access to retain real-time read and write access to sub-documents. This issue arises because the system fails to properly revoke websocket collaboration connections when access is revoked at parent documents. Defenders should assess exposure and prioritize remediation for Docs versions before 5.4.1, focusing on verifying and remediating this vulnerability to prevent unauthorized access.
- Vendor
- suitenumerique
- Product
- Docs
- CVSS
- HIGH 7.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-16
- Original CVE updated
- 2026-09-19
- Advisory published
- 2026-09-16
- Advisory updated
- 2026-09-19
Who should care
Defenders and administrators of Docs versions before 5.4.1 should assess exposure and prioritize remediation. This includes verifying and remediating the vulnerability, monitoring for suspicious activity, and reviewing compensating controls for exposed systems. Security teams and operators should focus on affected product deployments and plan vendor-supported updates or mitigations.
Why it matters
CVE-2026-92800 allows attackers with revoked access to retain real-time read and write access to sub-documents through open websocket sessions. Defenders should prioritize verifying and remediating this vulnerability in Docs versions before 5.4.1.
- Verify and remediate vulnerable Docs versions to prevent unauthorized access
- Monitor for suspicious websocket activity to detect potential exploitation
- Assess exposure and prioritize remediation for Docs versions before 5.4.1
Technical summary
CVE-2026-92800: Docs before 5.4.1 fails to properly revoke websocket collaboration connections when access is revoked at parent documents, allowing attackers with revoked access to retain real-time read and write access to sub-documents. This vulnerability affects Docs versions before 5.4.1 and requires verification and remediation to prevent unauthorized access. Defenders should prioritize verifying and remediating this vulnerability in Docs versions before 5.4.1, focusing on affected product context and defensive impact.
Defensive priority
Defenders should prioritize verifying and remediating this vulnerability in Docs versions before 5.4.1.
Recommended defensive actions
- Verify Docs version and assess exposure
- Remediate vulnerable versions to 5.4.1 or later
- Monitor for suspicious websocket activity
- Review compensating controls for exposed systems
- Check relevant monitoring, detection, and logs for exposed assets
- Track exceptions and retest remediated assets
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, but its scope, exploitation, and remediation require verification from official sources. Evidence is limited, and defenders should verify affected product deployments, review official advisories, and plan vendor-supported updates or mitigations. Compensating controls and monitoring may be necessary for exposed systems.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-92800 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-92800
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-92800 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-92800
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/geo-chen/oss/blob/main/docs.md
-
Source reference
Unverified legacy reference
URL: https://github.com/suitenumerique/docs
-
Source reference
Unverified legacy reference
URL: https://github.com/suitenumerique/docs/blob/v5.3.0/src/backend/core/api/viewsets.py
-
Source reference
Unverified legacy reference
URL: https://github.com/suitenumerique/docs/commit/d35b81a6ed526dc284c8d0f68b762f2e81ffab13
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/docs-before-5.4.1-stale-collaboration-session-after-access-revocation
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.