Server-Side Authorization Flaw in FileRise File Manager Affects User Data Privacy
CVE-2026-33477
4.3MEDIUM
What is CVE-2026-33477?
FileRise, a self-hosted file management solution, contains a server-side authorization flaw that allows authenticated users with limited read_own access to unauthorizedly retrieve file snippet content from other users' files within the same folder. This issue exists in versions 2.3.7 through 3.10.0 and can pose significant risks to user data privacy. The flaw has been addressed and mitigated in version 3.11.0. Users are advised to update to the latest version to safeguard their files from unauthorized access.
Affected Version(s)
FileRise >= 2.3.7, < 3.11.0
