WOPI Token Forgery Vulnerability in Cloudreve Product by Cloudreve
CVE-2026-62323
6.3MEDIUM
What is CVE-2026-62323?
The Cloudreve vulnerability allows attackers to exploit the ViewerSessionValidation by leveraging only the session-id prefix of a WOPI access token without proper validation of the requested viewer action. This oversight enables a malicious or compromised WOPI viewer to manipulate the token suffix and gain unauthorized access to WOPI write routes for the underlying file. This vulnerability has been addressed in version 4.17.0, reinforcing the integrity of the session handling process.
Affected Version(s)
cloudreve < 4.17.0
