Unauthenticated URL Fetching in kkFileView by kekingcn
CVE-2026-73243

5.8MEDIUM

Key Information:

Vendor

Kekingcn

Vendor
CVE Published:
11 August 2026

What is CVE-2026-73243?

kkFileView, a file online preview project based on Spring Boot, contains a vulnerability that allows unauthorized users to exploit an unauthenticated endpoint. Specifically, the /addTask endpoint was inadvertently excluded from critical filters, permitting attackers to retrieve a URL of their choice. This security flaw results from a weak handling of the fullfilename parameter within the FileHandlerService. The issue has been remediated in version 5.0.1, emphasizing the importance of timely updates to safeguard against potential exploits.

Affected Version(s)

kkFileView < 5.0.1

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.