CVE-2026-91144: ZFile through 5.0.5 Share Entry Filter Bypass via Download Endpoint
ZFile through 5.0.5 fails to validate requested file paths against a share link's allowed entries on the download endpoint. Attackers holding a share link can supply arbitrary file paths as query parameters to download any file under the shared base directory, bypassing the intended access restrictions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ZFileto a version that resolves this vulnerability.Fixed in 5.0.5
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs to possess a share link. No authentication or user interaction is required beyond access to that link.
What files can be accessed through the bypass?
The attacker can request arbitrary file paths under the shared base directory, rather than being limited to the entries allowed by the share link. The available data does not indicate access outside that base directory.
Are installations running version 5.0.5 affected?
Yes. The issue affects ZFile through version 5.0.5, so version 5.0.5 is included in the affected range.