PT-2026-91742 · Zfile · Zfile

·

CVE-2026-91144

·

Published

2026-09-14

·

Updated

2026-09-17

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ZFile versions prior to 5.0.6
Description The download endpoint fails to validate requested file paths against the allowed entries of a share link. This allows an attacker with a valid share link to provide arbitrary file paths as query parameters to download any file located under the shared base directory, bypassing intended access restrictions.
Recommendations Update to version 5.0.6 or later.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-91144

Affected Products

Zfile