WOPI Token Forgery Vulnerability in Cloudreve Product by Cloudreve
CVE-2026-62323

6.3MEDIUM

Key Information:

Vendor

Cloudreve

Status
Vendor
CVE Published:
31 July 2026

What is CVE-2026-62323?

The Cloudreve vulnerability allows attackers to exploit the ViewerSessionValidation by leveraging only the session-id prefix of a WOPI access token without proper validation of the requested viewer action. This oversight enables a malicious or compromised WOPI viewer to manipulate the token suffix and gain unauthorized access to WOPI write routes for the underlying file. This vulnerability has been addressed in version 4.17.0, reinforcing the integrity of the session handling process.

Affected Version(s)

cloudreve < 4.17.0

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.