Server-Side Authorization Flaw in FileRise File Manager Affects User Data Privacy
CVE-2026-33477

4.3MEDIUM

Key Information:

Vendor

Error311

Status
Vendor
CVE Published:
26 March 2026

What is CVE-2026-33477?

FileRise, a self-hosted file management solution, contains a server-side authorization flaw that allows authenticated users with limited read_own access to unauthorizedly retrieve file snippet content from other users' files within the same folder. This issue exists in versions 2.3.7 through 3.10.0 and can pose significant risks to user data privacy. The flaw has been addressed and mitigated in version 3.11.0. Users are advised to update to the latest version to safeguard their files from unauthorized access.

Affected Version(s)

FileRise >= 2.3.7, < 3.11.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.