Self-Hosted File Manager FileRise Vulnerability Exposes User TOTP Secrets
CVE-2026-44460
What is CVE-2026-44460?
FileRise, a self-hosted file manager, contains a vulnerability that allows attackers to retrieve a user's Time-Based One-Time Password (TOTP) secret. This issue arises when the '/api/totp_setup.php' endpoint is accessed from a session that has passed only the password check during the pending login phase. If a user already has TOTP configured, the vulnerable endpoint will decrypt and serve the TOTP secret within a QR PNG format instead of generating a new secret or denying access. Consequently, an attacker who has the victim's password can exploit this vulnerability to obtain a valid one-time code, thereby gaining unauthorized access to the user's account without needing the authenticator device. This security flaw has been addressed in version 3.12.0.
Affected Version(s)
FileRise < 3.12.0
