File Management and Sharing System Vulnerability in Cloudreve
CVE-2026-55499

4.3MEDIUM

Key Information:

Vendor

Cloudreve

Status
Vendor
CVE Published:
31 July 2026

What is CVE-2026-55499?

Cloudreve is a self-hosted file management and sharing solution susceptible to a vulnerability that allows an authorized share recipient to access sensitive information about unshared sibling files and folders. Before version 4.17.0, the application failed to properly isolate the share root, leading to the potential exposure of file names, paths, rename targets, event types, and hashed identifiers. This vulnerability poses a risk to user data security and privacy. The issue has been resolved in version 4.17.0, where improved access controls have been implemented.

Affected Version(s)

cloudreve < 4.17.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.