CVE-2026-82906: sdcb chats Signed File Download Endpoint FileController.cs DownloadPublic missing authentication
A flaw has been found in sdcb chats up to 1.12.0. This impacts the function DownloadPublic of the file src/BE/web/Controllers/Chats/Files/FileController.cs of the component Signed File Download Endpoint. This manipulation causes missing authentication. Remote exploitation of the attack is possible. The attack's complexity is rated as high. The exploitability is said to be difficult. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Deployments of sdcb chats up to version 1.12.0 may be affected, specifically the Signed File Download Endpoint implemented by the DownloadPublic function in FileController.cs. The vulnerable endpoint can be exploited remotely.
Does an attacker need an account or user interaction to exploit it?
No privileges or user interaction are required according to the supplied severity vector. However, exploitation has high attack complexity and is described as difficult.
Is there public exploit activity?
An exploit has been published and may be used. The reported exploit maturity is proof-of-concept.