PT-2026-93816 · Error311+1 · Filerise

·

CVE-2026-92616

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v4.0

7.6

High

VectorAV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions FileRise versions prior to 3.28.0
Description Improper session isolation between the WebDAV interface and the web application session context allows authenticated low-privilege attackers to gain unauthorized read and write access. By combining valid Basic-Auth credentials with an active admin PHPSESSID cookie, attackers can bypass authorization boundaries. This occurs because the WebDAV layer incorrectly inherits elevated privileges from an ambient web session instead of enforcing independent stateless authentication as required by RFC 4918.
Recommendations Update to version 3.28.0 or later.

Exploit

Fix

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92616

Affected Products

Filerise