Skip to content
The Docs Report
Tuesday, September 29, 2026NewsletterRSS

Redocly Fixes AI Search That Ignored Access Rules on Private Docs

Redocly's Sept. 23 Reunite release fixed AI search granting access to all visitors under certain RBAC setups. A web server security fix followed Sept. 28.

2 min read

RedoclyAISecurity

Product photo of a white padlock on a cherry red, orange and hot pink gradient

Redocly fixed a bug in which AI search granted access to all visitors under certain role-based access control (RBAC) project setups, according to the Sept. 23 Reunite changelog. The entry doesn’t say how long the bug existed, how many projects were affected or whether any restricted content was actually exposed.

The Sept. 23 fix

The Reunite v2026-09-23.4 release fixed AI search “incorrectly granting access to all visitors when specific RBAC project configurations were used.” That sentence is all Redocly has published: it names no configuration, no severity and no earlier version. The same release restored the AI assistant’s access to project API tools when authentication is required.

A security fix in the web server

Realm 0.137.1, released Sept. 28, includes a line reading “Fixed security issues in the web server.” The same release fixed AsciiDoc plugin build failures that occurred even though the JavaScript compiled successfully. Redocly gave no detail on the web server issues, and the changelog doesn’t say whether they relate to the AI search fix five days earlier.

Smaller changes

A Sept. 25 release made AI assistant support escalation emails use the requester’s address as the reply-to. A Sept. 28 release fixed remote content sync and commit status failures for repositories with many remotes, and it changed generated CI/CD snippets to use organization and project IDs instead of slugs. It also made the “Configure SSO and Access” go-live checklist step complete when access.requiresLogin is set.

Key takeaways

  • Under some RBAC configurations, Redocly’s AI search returned results to all visitors until the Sept. 23 fix.
  • Redocly hasn’t said how many projects were affected or whether restricted content leaked.
  • Realm 0.137.1 on Sept. 28 fixed unspecified web server security issues.

The take

We think teams running private docs on Redocly should check their AI search configuration now instead of waiting for a fuller account. Redocly has published one line about the access bug, and a line that short can’t tell a customer whether their content was exposed. We’d ask Redocly for the affected date range and configurations. AI search is a second retrieval path beside the page itself, and access rules have to be enforced on both. Any docs platform that puts an AI assistant over gated content takes on that risk.