Missing Authorization in Pydio Cells Share Link Functionality
CVE-2026-76032
5.3MEDIUM
What is CVE-2026-76032?
In versions 5.0.0 through 5.0.2 of Pydio Cells, an issue exists within the share link feature where any authenticated user can retrieve sensitive details without proper authorization. The affected REST handler for obtaining share link details fails to implement necessary authorization checks, allowing users to access critical information including link hash, URL, owner's ID, permission settings, and expiration details. This lack of safeguards can lead to unauthorized exposure of data that is typically restricted, significantly increasing the risk to user privacy and data integrity.
Affected Version(s)
cells 5.0.0 <= 5.0.2
