Missing Permission-Check in Copyparty File Server
CVE-2026-32108

2.3LOW

Key Information:

Vendor

9001

Status
Vendor
CVE Published:
11 March 2026

What is CVE-2026-32108?

The Copyparty file server has a vulnerability related to its shares feature where, prior to version 1.20.12, a missing permission check allows unauthorized users to gain read access to sibling files within a shared folder via FTP or SFTP. This issue is critical when the shares feature is utilized to share single files publicly and can lead to sensitive information exposure. Users can exploit this vulnerability by guessing or brute-forcing filenames, making it imperative for affected systems to upgrade to at least version 1.20.12 to mitigate this risk.

Affected Version(s)

copyparty < 1.20.12

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.