Unknown · Cotton Cloud · CVE-2026-67284
**Name of the Vulnerable Software and Affected Versions**
Cotton Cloud versions prior to 2.0.3
**Description**
An improper Access Control List (ACL) implementation allows authenticated users to perform unauthorized file operations on files owned by other users. These operations include reading, deleting, overwriting, and re-assigning permissions.
**Recommendations**
Update Cotton Cloud to version 2.0.3 or later.