Skip to main content
Vulnerability Database/CVE-2026-92800

CVE-2026-92800: Docs Privilege Escalation Vulnerability

CVE-2026-92800 is a privilege escalation vulnerability in Docs before version 5.4.1 that fails to revoke websocket connections when access is revoked. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-92800 Overview

CVE-2026-92800 is a session expiration vulnerability [CWE-613] affecting the Suite Numérique Docs collaborative editing platform in versions before 5.4.1. The flaw exists in how the backend handles websocket collaboration connections when access is revoked at a parent document. Revocation cascades to sub-documents at the permission layer, but the platform fails to terminate active websocket sessions established before revocation. Users whose access has been removed retain real-time read and write capabilities on nested documents through their persistent websocket connections.

Critical Impact

Attackers who previously held collaboration access can continue reading and modifying sensitive sub-documents indefinitely after their permissions are formally revoked, breaking the trust model of access control changes.

Affected Products

  • Suite Numérique Docs versions prior to 5.4.1
  • Deployments exposing websocket collaboration endpoints from src/backend/core/api/viewsets.py
  • Multi-tenant document workspaces relying on cascading permission inheritance

Discovery Timeline

  • 2026-09-16 - CVE-2026-92800 published to NVD
  • 2026-09-16 - Last updated in NVD database

Technical Details for CVE-2026-92800

Vulnerability Analysis

The vulnerability resides in the collaboration service layer of the Suite Numérique Docs backend. Docs supports hierarchical documents where permissions granted on a parent cascade to child documents. When an administrator revokes a user's access at the parent level, the authorization records for sub-documents are updated correctly. However, the collaboration websocket service maintains separate session state that is not reconciled with the permission change.

Active websocket connections established before revocation remain open. These sessions bypass subsequent authorization checks because permission validation occurs at connection establishment rather than continuously during the session lifetime. The result is a stale-session condition where authenticated real-time editing continues past the point of authorization.

Root Cause

The root cause is insufficient session expiration [CWE-613] combined with a missing cascade signal from the permission layer to the collaboration service. The patch introduces a new reset_service_connections_in_cascade task and imports the models module inside collaboration_services.py, enabling the backend to iterate descendant documents and force-disconnect websocket peers whose access has been revoked.

Attack Vector

Exploitation requires that the attacker previously held valid, low-privileged access to a parent document and established a websocket collaboration session. After access revocation, the attacker retains the open connection and continues issuing collaborative edit operations against sub-documents over the network. No user interaction from the victim is required.

python
# Patch excerpt: src/backend/core/api/viewsets.py
 get_document_indexer,
 get_visited_document_ids_of,
 )
+from core.tasks.access import reset_service_connections_in_cascade
 from core.tasks.mail import send_ask_for_access_mail
 from core.utils.analytics import PosthogEventName, posthog_capture
 from core.utils.paths import filter_descendants

# Patch excerpt: src/backend/core/services/collaboration_services.py
 """Collaboration services."""

+from logging import getLogger
+
 from django.conf import settings
 from django.core.exceptions import ImproperlyConfigured

 import requests

+from core import models
+
+logger = getLogger(__name__)
+

 class CollaborationService:
     """Service class for Collaboration related operations."""
# Source: https://github.com/suitenumerique/docs/commit/d35b81a6ed526dc284c8d0f68b762f2e81ffab13

The patch wires the access-revocation flow into a cascading task that resets collaboration connections across all child documents, closing the stale-session gap.

Detection Methods for CVE-2026-92800

Indicators of Compromise

  • Websocket connections to the Docs collaboration endpoint that persist beyond permission revocation events in application logs
  • Document edit events attributed to user accounts whose access records show revoked status at the time of the edit
  • Unexpected y-provider or CRDT sync traffic from client IPs associated with former collaborators

Detection Strategies

  • Correlate permission-change audit events with subsequent websocket message activity from the same user identifier
  • Alert when document mutation events occur from principals lacking a valid current access grant on the target document
  • Baseline the expected lifetime of collaboration sessions and flag long-lived sessions that survive access-control changes

Monitoring Recommendations

  • Ingest Docs backend logs and reverse-proxy websocket connection logs into a centralized analytics platform for correlation
  • Monitor the viewsets.py access-revocation endpoints for calls that are not followed by corresponding session-termination events
  • Track session duration metrics on the collaboration service and alert on outliers exceeding typical editing windows

How to Mitigate CVE-2026-92800

Immediate Actions Required

  • Upgrade Suite Numérique Docs to version 5.4.1 or later, which contains the cascading connection reset fix
  • Audit recent access-revocation events and identify sub-documents that may have been accessed by revoked users
  • Force-terminate all active websocket collaboration sessions after the upgrade to eliminate any pre-existing stale sessions

Patch Information

The fix is delivered in commit d35b81a6ed526dc284c8d0f68b762f2e81ffab13 in the suitenumerique/docs repository. It introduces a reset_service_connections_in_cascade task invoked from the access-management viewsets, ensuring websocket peers are disconnected across the full document subtree when a parent permission is revoked. Refer to the VulnCheck Security Advisory and the GitHub commit log for full patch details.

Workarounds

  • Restart the collaboration service after any high-sensitivity access revocation to forcibly close all active websocket sessions
  • Configure the reverse proxy or ingress in front of Docs to enforce short websocket idle timeouts, reducing the window of stale-session abuse
  • Restrict websocket endpoint access using network-layer controls so that only currently authorized IP ranges or authenticated identities can maintain sessions
bash
# Example: enforce a short websocket idle timeout at an nginx reverse proxy
location /collaboration/ws/ {
    proxy_pass http://docs_backend;
    proxy_http_version 1.1;
    proxy_set_header Upgrade $http_upgrade;
    proxy_set_header Connection "upgrade";
    proxy_read_timeout 60s;
    proxy_send_timeout 60s;
}

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.