PT-2026-77147 · Copyparty · Copyparty
CVE-2026-70657
·
Published
2026-08-18
·
Updated
2026-08-19
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Copyparty versions prior to 1.20.17
Description
When the
dk or dks directory-key flags are combined with the fk or fka file-key flags in a volume, a valid file key can be converted into a directory key. This allows unauthorized read access to the containing folder. This issue occurs only if both file-key and directory-key features are manually enabled in the volume flags, as they are disabled by default.Recommendations
Update to version 1.20.17.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Copyparty