CVE-2026-33146: Share Search Unrestricted Page Descendants

`getPageAndDescendants()` is called with a share object's `pageId` in what appears to be a publicly shared (unauthenticated) search context. This method returns ALL descendant pages, including those protected by page-level access restrictions, because no authorization filter is applied on the unauthenticated code path. Restricted page titles, content snippet

Provally CuratedPublic repositoryMediumHigh confidenceVerifiedApache-2.0TS
greprules fetch cve-2026-33146-share-search-unrestricted-page-descendants --engine opengrep

Description

`getPageAndDescendants()` is called with a share object's `pageId` in what appears to be a publicly shared (unauthenticated) search context. This method returns ALL descendant pages, including those protected by page-level access restrictions, because no authorization filter is applied on the unauthenticated code path. Restricted page titles, content snippet