CVE-2026-92616: FileRise < 3.28.0 Privilege Escalation via WebDAV Session Inheritance

Published Sep 16, 2026
·
Updated

FileRise before version 3.28.0 contains a privilege escalation vulnerability that allows authenticated low-privilege attackers to gain unauthorized read and write access by exploiting improper session isolation between the WebDAV interface and the web application session context. Attackers can combine valid Basic-Auth credentials with an active admin PHPSESSID cookie to bypass authorization boundaries, as the WebDAV layer incorrectly inherits elevated privileges from an ambient web session rather than enforcing independent stateless authentication per RFC 4918.

Affected Software

1 affected component
FileRise FileRise<3.28.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade FileRise to a version that resolves this vulnerability.

    Fixed in 3.28.0Patch FileRise < 3.28.0 Privilege Escalation via WebDAV Session Inheritance

Event History

Sep 16, 2026
CVE Published
via MITRE·02:38 PM
Data Sourced
via MITRE·02:38 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What conditions are required to exploit this issue?

An attacker needs valid low-privilege Basic-Auth credentials and access to an active administrator PHPSESSID cookie. The attack uses the WebDAV interface together with that ambient administrative web session.

2

What access could an attacker gain?

A successful attacker can obtain unauthorized read and write access by causing the WebDAV layer to inherit elevated privileges from the administrator session.

3

Which deployments should be prioritized for remediation?

Prioritize FileRise deployments that expose or use WebDAV and have versions earlier than 3.28.0. The issue requires both authenticated low-privilege access and an active administrator session cookie.

4

What version resolves the vulnerability?

FileRise 3.28.0 is identified as the release boundary for this issue; versions before 3.28.0 are affected.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203