CVE-2026-25231: FileRise affected by an Unauthenticated File Read Due to Insufficient Access Control
FileRise is a self-hosted web file manager / WebDAV server. Versions prior to 3.3.0, the application contains an unauthenticated file read vulnerability due to the lack of access control on the /uploads directory. Files uploaded to this directory can be accessed directly by any user who knows or can guess the file path, without requiring authentication. As a result, sensitive data could be exposed, and privacy may be breached. This vulnerability is fixed in 3.3.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25231?
CVE-2026-25231 is classified as a high severity vulnerability due to its potential for unauthorized access to sensitive files.
How do I fix CVE-2026-25231?
To fix CVE-2026-25231, upgrade to FileRise version 3.3.0 or later where the vulnerability has been addressed.
What types of systems are affected by CVE-2026-25231?
CVE-2026-25231 affects self-hosted FileRise web file manager applications prior to version 3.3.0.
What is the nature of the vulnerability in CVE-2026-25231?
The nature of CVE-2026-25231 is an unauthenticated file read due to insufficient access control on the /uploads directory.
Can I exploit CVE-2026-25231 without authentication?
Yes, CVE-2026-25231 can be exploited without authentication, allowing unauthorized users to access files.