Multiple vulnerabilities in GROWI
GROWI provided by GROWI, Inc. contains multiple vulnerabilities.
CSIRTS triage
- What
- Multiple vulnerabilities exist in GROWI.
- Who is affected
- All GROWI deployments are potentially affected.
- Urgency
- Unclear; no severity, CVSS, or exploitation details provided.
- Action
- Monitor GROWI security advisories and apply patches when available.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch GROWI
Get an email when a new GROWI advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://jvn.jp/en/jp/JVN42348352/
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-53620 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-68951 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
Recent advisories for GROWI
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- mediumCVE-2026-84205: GROWI contains an access control vulnerability in the GET /_api/v3/revisions/:id endpoint that…nvd · 2026-09-01
- mediumCVE-2026-84204: GROWI contains an access control vulnerability in the GET /_api/v3/attachment/:id endpoint tha…nvd · 2026-09-01
- mediumCVE-2026-68951: GROWI contains an incorrect authorization vulnerability. If this vulnerability is exploited, a…nvd · 2026-08-31
- mediumCVE-2026-53620: GROWI contains a vulnerability with an authorization bypass through user-controlled key in the…nvd · 2026-08-31
- highCVE-2026-80191: GROWI applies its page-viewer permission check to attachment requests only when the request ca…nvd · 2026-08-26
More from JVN (Japan Vulnerability Notes)
- unknownMultiple vulnerabilities in XING CPTrans-ME-X2026-09-04
- unknownImproper restriction of XML external entity reference in XG VisionTerminal and XG-X VisionTerminal2026-09-02
- unknownMultiple vulnerabilities in ShizenBox22026-09-02
- unknownPALLET CONTROL products vulnerable to improper access control2026-09-01
- unknownReflected cross-site scripting vulnerability in multiple laser printers and MFPs which implement Ricoh Web Ima…2026-08-31