Sceawere
Vulnerability Detail
CVE-2026-108731UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Raven Unauthorized Workspace Access Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.4
- Creation Date
- 4h ago
- Vendor
- The-Commit-Company
- Product
- raven
- Attack Type
- Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Raven 2.0.0 through 3.0.0 contains a missing authorization vulnerability that allows authenticated users to join invite-only Public workspaces by ignoring the can_only_join_via_invite setting. Attackers with the Raven User role can call the join_workspace method to become persistent members, reading and posting in Public and Open channels.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.4",
"pubDate": "2026-10-11T13:17:17.207Z",
"pubdate": "2026-10-11T13:17:17.207Z",
"executiveSummary": "A missing authorization vulnerability exists in Raven versions 2.0.0 through 3.0.0, enabling authenticated users to circumvent invite-only restrictions for Public workspaces.\nThe vulnerability resides in the workspace membership logic, specifically within the join_workspace method, which fails to properly validate the can_only_join_via_invite configuration flag.\nBy exploiting this flaw, any attacker possessing a valid Raven User role can force their enrollment into restricted workspaces, thereby gaining unauthorized access to information.\nThe security impact includes potential data exposure of internal communications, sensitive channel discussions, and unauthorized participation in workspace activities.\nThis vulnerability presents a significant risk to organizational data confidentiality and access control policies, as it allows unauthorized lateral movement within the application ecosystem.\nThe attack requires an authenticated user account but no additional administrative privileges, making it highly exploitable for standard users seeking to access restricted collaborative spaces.",
"technicalDetails": "The root cause of this vulnerability is an inadequate access control check within the application's workspace joining mechanism. Specifically, the join_workspace method fails to enforce the can_only_join_via_invite setting when processing a request to join a workspace defined as 'Public'.\nIn affected versions (Raven 2.0.0 through 3.0.0), the backend logic assumes that Public workspaces should remain open to all authenticated users, regardless of whether the workspace owner has explicitly configured the can_only_join_via_invite toggle to true.\nThe exploitation flow is straightforward: an authenticated user identifies the identifier for a target workspace that has the can_only_join_via_invite setting enabled. The user then invokes the join_workspace method, passing the target workspace identifier as an argument. Because the server-side validation logic neglects to check the can_only_join_via_invite attribute before finalizing the database transaction, the application incorrectly grants the user 'member' status.\nOnce the join_workspace method completes, the attacker is assigned a persistent membership record within that workspace. This persistence allows the attacker to maintain ongoing access to the workspace environment even after the initial session terminates. Consequently, the attacker obtains authorization to monitor, read, and post content in any channels designated as 'Public' or 'Open' within that workspace.\nThis vulnerability is classified as a Missing Authorization flaw. It bypasses the intended business logic constraints that maintain the privacy of restricted collaboration spaces. The impact is significant because it grants unauthorized entities the same permissions as legitimate members, facilitating information disclosure and potentially enabling further malicious activity such as phishing or social engineering within the workspace.\nBecause the vulnerability exists in the core API method responsible for workspace membership, the exposure is global across all instances of Raven 2.0.0 through 3.0.0. No specific network access beyond the application's standard API endpoints is required, provided the attacker maintains an authenticated user session."
}