PT-2026-52542 · Git+1 · Seahub

·

CVE-2026-56768

·

Published

2026-06-25

·

Updated

2026-06-25

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Seahub versions prior to 13.0.23
Description Authentication bypass occurs because the system fails to enforce the SHARE LINK LOGIN REQUIRED setting on the 'GET /api/v2.1/share-link-zip-task/' endpoint. An unauthenticated attacker possessing a folder share-link token can access this endpoint to retrieve a fileserver zip token, enabling the download of entire shared directory trees.
Recommendations Update Seahub to version 13.0.23 or later.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56768

Affected Products

Seahub