Improper Authentication in KodExplorer by kodcloud
CVE-2026-6569

6.9MEDIUM

Key Information:

Vendor

Kodcloud

Vendor
CVE Published:
19 April 2026

What is CVE-2026-6569?

A serious vulnerability exists in kodcloud's KodExplorer up to version 4.52, specifically in the fileGet function located in /app/controller/share.class.php. The flaw allows an attacker to manipulate the fileUrl argument, leading to improper authentication. This vulnerability enables remote exploitation, which could compromise the confidentiality and integrity of sensitive information on affected systems. While the vendor was notified of this issue, there has been no response to address the risk.

Affected Version(s)

KodExplorer 4.0

KodExplorer 4.1

KodExplorer 4.2

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

vulnplusbot (VulDB User)
VulDB CNA Team
.