Self-Hosted File Manager FileRise Vulnerability Exposes User TOTP Secrets
CVE-2026-44460

7.4HIGH

Key Information:

Vendor

Error311

Status
Vendor
CVE Published:
27 May 2026

What is CVE-2026-44460?

FileRise, a self-hosted file manager, contains a vulnerability that allows attackers to retrieve a user's Time-Based One-Time Password (TOTP) secret. This issue arises when the '/api/totp_setup.php' endpoint is accessed from a session that has passed only the password check during the pending login phase. If a user already has TOTP configured, the vulnerable endpoint will decrypt and serve the TOTP secret within a QR PNG format instead of generating a new secret or denying access. Consequently, an attacker who has the victim's password can exploit this vulnerability to obtain a valid one-time code, thereby gaining unauthorized access to the user's account without needing the authenticator device. This security flaw has been addressed in version 3.12.0.

Affected Version(s)

FileRise < 3.12.0

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.