Missing Permission-Check in Copyparty File Server
CVE-2026-32108
2.3LOW
What is CVE-2026-32108?
The Copyparty file server has a vulnerability related to its shares feature where, prior to version 1.20.12, a missing permission check allows unauthorized users to gain read access to sibling files within a shared folder via FTP or SFTP. This issue is critical when the shares feature is utilized to share single files publicly and can lead to sensitive information exposure. Users can exploit this vulnerability by guessing or brute-forcing filenames, making it imperative for affected systems to upgrade to at least version 1.20.12 to mitigate this risk.
Affected Version(s)
copyparty < 1.20.12
