CVE-2026-101004 | notionnext-org NotionNext up to 4.10.10 Authentication Guard pages/api/cache.js cleanCache token missing authentication
A vulnerability, which was classified as problematic, has been found in notionnext-org NotionNext up to 4.10.10. Affected by this issue is the function cleanCache of the file pages/api/cache.js of the component Authentication Guard. The manipulation of the argument token leads to missing authentication.
This vulnerability is listed as CVE-2026-101004. The attack may be initiated remotely. There is no available exploit.
Versions 4.1.0 – 4.9.5.2 allow unauthenticated exploitation due to missing method check. In versions 4.9.5.7 – 4.10.10 a guard present but only enforced when CACHE_REVALIDATION_TOKEN is set. Default deployments remain unprotected. The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More