CVE-2026-33330: FileRise ONLYOFFICE integration allows read-only users to overwrite files via forged save callback
FileRise is a self-hosted web file manager / WebDAV server. Prior to version 3.10.0, a broken access control issue in FileRise's ONLYOFFICE integration allows an authenticated user with read-only access to obtain a signed save callbackUrl for a file and then directly forge the ONLYOFFICE save callback to overwrite that file with attacker-controlled content. This issue has been patched in version 3.10.0.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33330?
CVE-2026-33330 is categorized as a broken access control vulnerability, which can lead to unauthorized file overwriting by authenticated users with read-only access.
How do I fix CVE-2026-33330?
To remediate CVE-2026-33330, it is recommended to upgrade FileRise to version 3.10.0 or later.
What versions of FileRise are affected by CVE-2026-33330?
CVE-2026-33330 affects FileRise versions prior to 3.10.0.
Who is impacted by CVE-2026-33330?
Authenticated users with read-only access in FileRise can exploit CVE-2026-33330 to overwrite files.
Is CVE-2026-33330 a critical vulnerability?
While not classified as critical, CVE-2026-33330 poses a serious risk due to the potential for file integrity compromise.