Access Control Vulnerability in Sharp Content Management Framework by Code16
CVE-2026-44692
What is CVE-2026-44692?
The Sharp content management framework, developed by Code16, exposes an access control vulnerability that impacts versions prior to 9.22.0. This issue arises when an authenticated user, who has access to at least one valid record within the system, can leverage that record to gain unauthorized access to other object files stored within configured Laravel Storage disks. The vulnerability allows the user to exploit the generic download endpoint, which improperly authorizes access based solely on the entity instance provided in the request. Consequently, this can lead to the unintentional exposure and downloading of unrelated files, although it does not grant arbitrary access to the host filesystem beyond the defined storage disk roots. A patch has been released in version 9.22.0 to remediate this issue.
Affected Version(s)
sharp < 9.22.0
