CVE-2026-33640

Outline is a service that allows for collaborative documentation. Outline implements an Email OTP login flow for users not associated with an Identity Provider. Starting in version 0.86.0 and prior to version 1.6.0, Outline does not invalidate OTP codes based on amount or frequency of invalid submissions, rather it relies on the rate limiter to restrict attempts. Consequently, identified bypasses in the rate limiter permit unrestricted OTP code submissions within the codes lifetime. This allows attackers to perform brute force attacks which enable account takeover. Version 1.6.0 fixes the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:getoutline:outline:*:*:*:*:*:*:*:*

History

31 Mar 2026, 01:42

Type Values Removed Values Added
References () https://github.com/outline/outline/releases/tag/v1.6.0 - () https://github.com/outline/outline/releases/tag/v1.6.0 - Release Notes
References () https://github.com/outline/outline/security/advisories/GHSA-cwhc-53hw-qqx6 - () https://github.com/outline/outline/security/advisories/GHSA-cwhc-53hw-qqx6 - Exploit, Vendor Advisory
First Time Getoutline
Getoutline outline
CPE cpe:2.3:a:getoutline:outline:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

Information

Published : 2026-03-26 21:17

Updated : 2026-03-31 01:42


NVD link : CVE-2026-33640

Mitre link : CVE-2026-33640

CVE.ORG link : CVE-2026-33640


JSON object : View

Products Affected

getoutline

  • outline
CWE
CWE-307

Improper Restriction of Excessive Authentication Attempts