Threat Advisory

Cloudreve Vulnerabilities Grant Unauthorized Access to Internal Documents

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Six vulnerabilities affect Cloudreve and arise from weaknesses in input validation, authorization, and resource handling across multiple application components. The flaws include authorization bypasses, information disclosure, path traversal, denial-of-service (DoS), and improper validation of WOPI access tokens and user input. Successful exploitation could allow attackers to modify files beyond intended permissions, disclose sensitive user information, crash the application through resource exhaustion, or bypass access controls to perform unauthorized actions. Collectively, these vulnerabilities could impact the confidentiality, integrity, and availability of affected Cloudreve instances if left unpatched.

CVE-2026-55495 (CVSS 4.3 — Medium): A path traversal vulnerability in Cloudreve's WOPI PUT_RELATIVE handler allows an attacker with a valid single-file WOPI access token to create or overwrite files in other locations within the same user's account by manipulating the X-WOPI-SuggestedTarget header.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Six vulnerabilities affect Cloudreve and arise from weaknesses in input validation, authorization, and resource handling across multiple application components. The flaws include authorization bypasses, information disclosure, path traversal, denial-of-service (DoS), and improper validation of WOPI access tokens and user input. Successful exploitation could allow attackers to modify files beyond intended permissions, disclose sensitive user information, crash the application through resource exhaustion, or bypass access controls to perform unauthorized actions. Collectively, these vulnerabilities could impact the confidentiality, integrity, and availability of affected Cloudreve instances if left unpatched.

CVE-2026-55495 (CVSS 4.3 — Medium): A path traversal vulnerability in Cloudreve's WOPI PUT_RELATIVE handler allows an attacker with a valid single-file WOPI access token to create or overwrite files in other locations within the same user's account by manipulating the X-WOPI-SuggestedTarget header.[emaillocker id="1283"]

CVE-2026-55496 (CVSS 4.3 — Medium): An information disclosure vulnerability in Cloudreve allows any authenticated user to enumerate inactive or banned accounts and retrieve their email addresses and basic profile information due to missing account status validation in the user search functionality.

CVE-2026-55497 (CVSS 6.5 — Medium): A denial-of-service (DoS) vulnerability in Cloudreve allows an authenticated attacker to upload a specially crafted image with oversized dimensions, causing excessive memory allocation that crashes the application and results in service disruption.

CVE-2026-55499 (CVSS 4.3 — Medium): A single-file share recipient is subscribed to the owner's parent folder and receives activity events for unshared siblings when accessing the file event stream.

CVE-2026-55502 (CVSS 7.1 — High): An authorization bypass vulnerability in Cloudreve allows an OAuth token with only Admin.Read privileges to modify OneDrive storage policy credentials due to missing Admin.Write scope validation on the admin OAuth sign-in endpoint.

CVE-2026-62323 (CVSS 6.3 — Medium): An authorization bypass vulnerability in Cloudreve allows attackers to forge WOPI access tokens and use view-only sessions to perform unauthorized file modifications because the application fails to validate the full token and enforce session-level write permissions.

RECOMMENDATIONS:

  • We recommend you to update github.com/cloudreve/Cloudreve/v4 and github.com/cloudreve/Cloudreve/v3 to below version:
  • CVE-2026-55495: https://github.com/advisories/GHSA-49h3-cwhj-4737
  • CVE-2026-55496: https://github.com/advisories/GHSA-8r7f-r8hj-r3rv
  • CVE-2026-55497: https://github.com/advisories/GHSA-g9j2-8w95-3vwv
  • CVE-2026-55499: https://github.com/advisories/GHSA-w8x7-h2px-xmq8
  • CVE-2026-55502: https://github.com/advisories/GHSA-hq88-5x99-x3gf
  • CVE-2026-62323: https://github.com/advisories/GHSA-c3jm-gv5r-9wcp

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu