CVE-2026-92800 Overview
CVE-2026-92800 is a session expiration vulnerability [CWE-613] affecting the Suite Numérique Docs collaborative editing platform in versions before 5.4.1. The flaw exists in how the backend handles websocket collaboration connections when access is revoked at a parent document. Revocation cascades to sub-documents at the permission layer, but the platform fails to terminate active websocket sessions established before revocation. Users whose access has been removed retain real-time read and write capabilities on nested documents through their persistent websocket connections.
Critical Impact
Attackers who previously held collaboration access can continue reading and modifying sensitive sub-documents indefinitely after their permissions are formally revoked, breaking the trust model of access control changes.
Affected Products
- Suite Numérique Docs versions prior to 5.4.1
- Deployments exposing websocket collaboration endpoints from src/backend/core/api/viewsets.py
- Multi-tenant document workspaces relying on cascading permission inheritance
Discovery Timeline
- 2026-09-16 - CVE-2026-92800 published to NVD
- 2026-09-16 - Last updated in NVD database
Technical Details for CVE-2026-92800
Vulnerability Analysis
The vulnerability resides in the collaboration service layer of the Suite Numérique Docs backend. Docs supports hierarchical documents where permissions granted on a parent cascade to child documents. When an administrator revokes a user's access at the parent level, the authorization records for sub-documents are updated correctly. However, the collaboration websocket service maintains separate session state that is not reconciled with the permission change.
Active websocket connections established before revocation remain open. These sessions bypass subsequent authorization checks because permission validation occurs at connection establishment rather than continuously during the session lifetime. The result is a stale-session condition where authenticated real-time editing continues past the point of authorization.
Root Cause
The root cause is insufficient session expiration [CWE-613] combined with a missing cascade signal from the permission layer to the collaboration service. The patch introduces a new reset_service_connections_in_cascade task and imports the models module inside collaboration_services.py, enabling the backend to iterate descendant documents and force-disconnect websocket peers whose access has been revoked.
Attack Vector
Exploitation requires that the attacker previously held valid, low-privileged access to a parent document and established a websocket collaboration session. After access revocation, the attacker retains the open connection and continues issuing collaborative edit operations against sub-documents over the network. No user interaction from the victim is required.
# Patch excerpt: src/backend/core/api/viewsets.py
get_document_indexer,
get_visited_document_ids_of,
)
+from core.tasks.access import reset_service_connections_in_cascade
from core.tasks.mail import send_ask_for_access_mail
from core.utils.analytics import PosthogEventName, posthog_capture
from core.utils.paths import filter_descendants
# Patch excerpt: src/backend/core/services/collaboration_services.py
"""Collaboration services."""
+from logging import getLogger
+
from django.conf import settings
from django.core.exceptions import ImproperlyConfigured
import requests
+from core import models
+
+logger = getLogger(__name__)
+
class CollaborationService:
"""Service class for Collaboration related operations."""
# Source: https://github.com/suitenumerique/docs/commit/d35b81a6ed526dc284c8d0f68b762f2e81ffab13
The patch wires the access-revocation flow into a cascading task that resets collaboration connections across all child documents, closing the stale-session gap.
Detection Methods for CVE-2026-92800
Indicators of Compromise
- Websocket connections to the Docs collaboration endpoint that persist beyond permission revocation events in application logs
- Document edit events attributed to user accounts whose access records show revoked status at the time of the edit
- Unexpected y-provider or CRDT sync traffic from client IPs associated with former collaborators
Detection Strategies
- Correlate permission-change audit events with subsequent websocket message activity from the same user identifier
- Alert when document mutation events occur from principals lacking a valid current access grant on the target document
- Baseline the expected lifetime of collaboration sessions and flag long-lived sessions that survive access-control changes
Monitoring Recommendations
- Ingest Docs backend logs and reverse-proxy websocket connection logs into a centralized analytics platform for correlation
- Monitor the viewsets.py access-revocation endpoints for calls that are not followed by corresponding session-termination events
- Track session duration metrics on the collaboration service and alert on outliers exceeding typical editing windows
How to Mitigate CVE-2026-92800
Immediate Actions Required
- Upgrade Suite Numérique Docs to version 5.4.1 or later, which contains the cascading connection reset fix
- Audit recent access-revocation events and identify sub-documents that may have been accessed by revoked users
- Force-terminate all active websocket collaboration sessions after the upgrade to eliminate any pre-existing stale sessions
Patch Information
The fix is delivered in commit d35b81a6ed526dc284c8d0f68b762f2e81ffab13 in the suitenumerique/docs repository. It introduces a reset_service_connections_in_cascade task invoked from the access-management viewsets, ensuring websocket peers are disconnected across the full document subtree when a parent permission is revoked. Refer to the VulnCheck Security Advisory and the GitHub commit log for full patch details.
Workarounds
- Restart the collaboration service after any high-sensitivity access revocation to forcibly close all active websocket sessions
- Configure the reverse proxy or ingress in front of Docs to enforce short websocket idle timeouts, reducing the window of stale-session abuse
- Restrict websocket endpoint access using network-layer controls so that only currently authorized IP ranges or authenticated identities can maintain sessions
# Example: enforce a short websocket idle timeout at an nginx reverse proxy
location /collaboration/ws/ {
proxy_pass http://docs_backend;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
proxy_read_timeout 60s;
proxy_send_timeout 60s;
}
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.