Missing Authorization in Pydio Cells Share Link Functionality
CVE-2026-76032

5.3MEDIUM

Key Information:

Vendor

Pydio

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-76032?

In versions 5.0.0 through 5.0.2 of Pydio Cells, an issue exists within the share link feature where any authenticated user can retrieve sensitive details without proper authorization. The affected REST handler for obtaining share link details fails to implement necessary authorization checks, allowing users to access critical information including link hash, URL, owner's ID, permission settings, and expiration details. This lack of safeguards can lead to unauthorized exposure of data that is typically restricted, significantly increasing the risk to user privacy and data integrity.

Affected Version(s)

cells 5.0.0 <= 5.0.2

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.