Authorization Bypass in OpenText Filr Affects Multiple Versions
CVE-2026-3266

8.3HIGH

Key Information:

Status
Vendor
CVE Published:
3 March 2026

What is CVE-2026-3266?

A missing authorization vulnerability in OpenText™ Filr has been discovered, which facilitates authentication bypass. This flaw allows unauthenticated users to obtain an XSRF token and potentially execute remote procedure calls (RPC) using specially crafted programs. Affected versions include OpenText Filr up to and including version 25.1.2, posing a significant security risk that organizations should address promptly.

Affected Version(s)

Filr 0 <= 25.1.2

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.