Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 09 Apr 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 08 Apr 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cloud Solutions
Cloud Solutions wimi Teamwork |
|
| Vendors & Products |
Cloud Solutions
Cloud Solutions wimi Teamwork |
Wed, 08 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 08 Apr 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Wimi Teamwork On-Premises versions prior to 8.2.0 contain an insecure direct object reference vulnerability in the preview.php endpoint where the item_id parameter lacks proper authorization checks. Attackers can enumerate sequential item_id values to access and retrieve image previews from other users' private or group conversations, resulting in unauthorized disclosure of sensitive information. | |
| Title | Wimi Teamwork On-Premises < 8.2.0 IDOR via preview.php | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-09T17:57:56.369Z
Reserved: 2026-03-31T20:40:15.618Z
Link: CVE-2026-35023
Updated: 2026-04-08T14:17:24.249Z
Status : Awaiting Analysis
Published: 2026-04-08T14:16:28.320
Modified: 2026-04-09T18:16:59.410
Link: CVE-2026-35023
No data.
OpenCVE Enrichment
Updated: 2026-04-08T19:39:35Z