CVE-2026-51892 Overview
CVE-2026-51892 is an incorrect access control vulnerability in infiniflow ragflow version 0.24.0. The flaw resides in the /v1/document/get/<doc_id> endpoint, which fails to properly enforce authorization on document retrieval requests. An authenticated low-privileged user can request arbitrary document identifiers and read documents belonging to other tenants or users. The weakness maps to [CWE-284: Improper Access Control] and affects the retrieval-augmented generation workflow central to ragflow deployments.
Critical Impact
Authenticated attackers can read sensitive documents stored in ragflow by directly requesting document IDs through the vulnerable API endpoint, resulting in cross-tenant information disclosure.
Affected Products
- infiniflow ragflow 0.24.0
- Deployments exposing the /v1/document/get/<doc_id> API endpoint
- RAG pipelines ingesting multi-tenant document corpora into ragflow
Discovery Timeline
- 2026-10-01 - CVE-2026-51892 published to the National Vulnerability Database
- 2026-10-05 - Last updated in NVD database
Technical Details for CVE-2026-51892
Vulnerability Analysis
The vulnerability stems from missing ownership and tenancy checks on the document retrieval API in ragflow 0.24.0. When a client issues a GET request to /v1/document/get/<doc_id>, the server authenticates the session but does not verify that the requesting user owns the referenced document or belongs to the same knowledge base. Any authenticated user can enumerate or guess doc_id values and retrieve content from other users' knowledge bases.
Because ragflow serves retrieval-augmented generation workloads, the exposed documents frequently include proprietary data, internal knowledge bases, and personally identifiable information ingested for LLM grounding. The attack impacts confidentiality only; integrity and availability are not affected.
Technical references include the public proof-of-concept gist and the upstream project discussion in GitHub issue 14618 and GitHub issue 15267.
Root Cause
The handler for /v1/document/get/<doc_id> performs session authentication but omits an authorization check that binds the doc_id parameter to the caller's tenant or knowledge base membership. This is a classic Insecure Direct Object Reference (IDOR) pattern under [CWE-284].
Attack Vector
Exploitation requires network access to the ragflow API and a valid low-privileged account. The attacker iterates or enumerates doc_id values and issues GET requests to /v1/document/get/<doc_id>, receiving document contents belonging to other users. No user interaction is required, and the attack complexity is low.
// No verified exploit code is published beyond the referenced PoC gist.
// See: https://gist.github.com/Ro1ME/00684720b33e37b2dd39856d6c226468
Detection Methods for CVE-2026-51892
Indicators of Compromise
- Repeated GET requests to /v1/document/get/<doc_id> from a single authenticated session targeting many distinct doc_id values.
- API access patterns where one user account retrieves documents associated with knowledge bases they do not own.
- Unusual spikes in response bytes from the ragflow document endpoint to a single client IP.
Detection Strategies
- Instrument the ragflow API gateway or reverse proxy to log the authenticated principal alongside the requested doc_id for correlation.
- Build analytics that compare the requested document's owning tenant against the caller's tenant and alert on mismatches.
- Baseline normal document access volumes per user and alert on sequential or enumerated doc_id access patterns.
Monitoring Recommendations
- Forward ragflow access logs to a centralized SIEM or data lake for cross-user authorization analysis.
- Monitor for enumeration behavior such as monotonically increasing identifiers or high-cardinality doc_id fan-out.
- Review audit trails for any account that accessed documents outside its assigned knowledge bases since deploying ragflow 0.24.0.
How to Mitigate CVE-2026-51892
Immediate Actions Required
- Restrict network exposure of the ragflow API to trusted users while a fix is applied.
- Audit existing accounts and disable or rotate credentials for any account that may have been used to enumerate documents.
- Review ragflow document access logs for the /v1/document/get/<doc_id> endpoint to identify potential prior exposure.
Patch Information
No vendor-confirmed patch is referenced in the NVD entry at publication. Monitor the upstream infiniflow/ragflow repository and the referenced issues (#14618, #15267) for a fixed release and upgrade beyond version 0.24.0 when available.
Workarounds
- Place ragflow behind an authenticating reverse proxy that enforces per-user authorization on the /v1/document/get/ path.
- Segregate tenants into distinct ragflow deployments so that cross-tenant document retrieval is architecturally impossible.
- Apply a middleware or application-level check that validates document ownership against the authenticated session before returning content.
# Example nginx snippet restricting document retrieval to an internal network
location ~ ^/v1/document/get/ {
allow 10.0.0.0/8;
deny all;
proxy_pass http://ragflow_backend;
}
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.