Unauthenticated File Access in OpenCode Studio by Microck
CVE-2026-69110
Key Information:
- Vendor
Microck
- Status
- Vendor
- CVE Published:
- 4 August 2026
Badges
What is CVE-2026-69110?
OpenCode Studio, prior to version 2.4.4, exhibits a missing authentication vulnerability. This flaw enables unauthorized remote attackers to access sensitive files within the temp and static/music directories by leveraging the GET /api/tmp/:tmpFile and GET /api/music/:fileName endpoints. Additionally, attackers can manipulate the system by deleting video content using the unauthenticated DELETE /api/short-video/:videoId endpoint. This vulnerability poses a significant security risk, allowing the exploitation of user data and system integrity.
Affected Version(s)
opencode-studio 0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
