CVE-2026-82582: Medium severity SHIRASAGI vulnerability
Published Sep 10, 2026
·Updated
An authorization bypass vulnerability exists in SHIRASAGI through a user-controlled key, which may allow an unauthorized attacker to retrieve files from the groupware's shared file feature.
Affected Software
1 affected component
SHIRASAGI<=unknown
Event History
Sep 10, 2026
CVE Published
via MITRE·06:09 AM
Data Sourced
via MITRE·06:09 AM
DescriptionSeverity
Frequently Asked Questions
1
What level of access does an attacker need?
The CVSS vector indicates network reachability and low privileges are required. No user interaction is required.
2
What security impact is assessed beyond file disclosure?
The assessment indicates low confidentiality impact, with no integrity or availability impact. The provided data does not describe modification, deletion, or service-disruption capabilities.
3
Can I determine affected versions or configurations from this information?
No. The provided data identifies SHIRASAGI and its groupware shared-file feature, but does not list affected or fixed versions, default-configuration status, or detection guidance.