File Management and Sharing System Vulnerability in Cloudreve
CVE-2026-55499
4.3MEDIUM
What is CVE-2026-55499?
Cloudreve is a self-hosted file management and sharing solution susceptible to a vulnerability that allows an authorized share recipient to access sensitive information about unshared sibling files and folders. Before version 4.17.0, the application failed to properly isolate the share root, leading to the potential exposure of file names, paths, rename targets, event types, and hashed identifiers. This vulnerability poses a risk to user data security and privacy. The issue has been resolved in version 4.17.0, where improved access controls have been implemented.
Affected Version(s)
cloudreve < 4.17.0
