PT-2026-96796 · Cloudreve · Cloudreve

CVE-2026-77637

·

Published

2026-09-22

·

Updated

2026-09-22

CVSS v3.1

3.8

Low

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Cloudreve versions prior to 4.18.0
Description A privilege scope bypass exists in the admin API due to inconsistent middleware application in routers/router.go. While most state-changing admin tool routes require ScopeAdminWrite, the endpoints 'tool.GET("wopi")' and 'tool.POST("mail")' only inherit ScopeAdminRead. This allows an OAuth application or API key restricted to read-only administrative access to exceed its authorization boundary. Consequently, an attacker with such a token can probe configured WOPI (Web Open Word Processing Interface) service endpoints and send arbitrary test emails using the server's SMTP configuration.
Recommendations Update to version 4.18.0. As a temporary workaround, restrict the issuance of OAuth tokens or API keys with Admin.Read scope to only highly trusted entities.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77637
GHSA-W89X-C962-C44G

Affected Products

Cloudreve