Access Control Vulnerability in Sharp Content Management Framework by Code16
CVE-2026-44692

7.7HIGH

Key Information:

Vendor

Code16

Status
Vendor
CVE Published:
10 June 2026

What is CVE-2026-44692?

The Sharp content management framework, developed by Code16, exposes an access control vulnerability that impacts versions prior to 9.22.0. This issue arises when an authenticated user, who has access to at least one valid record within the system, can leverage that record to gain unauthorized access to other object files stored within configured Laravel Storage disks. The vulnerability allows the user to exploit the generic download endpoint, which improperly authorizes access based solely on the entity instance provided in the request. Consequently, this can lead to the unintentional exposure and downloading of unrelated files, although it does not grant arbitrary access to the host filesystem beyond the defined storage disk roots. A patch has been released in version 9.22.0 to remediate this issue.

Affected Version(s)

sharp < 9.22.0

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.