File Management and Sharing Vulnerability in Cloudreve by Cloudreve
CVE-2026-77633

7.1HIGH

Key Information:

Vendor

Cloudreve

Status
Vendor
CVE Published:
22 September 2026

What is CVE-2026-77633?

In Cloudreve, a self-hosted file management and sharing system, users prior to version 4.18.0 can exploit a flaw in the PrepareUpload function. This flaw allows authenticated users with Files.Write permissions to bypass storage limits by manipulating upload-session requests. The vulnerability enables concurrent requests that can exceed the user's declared storage capacity, resulting in excessive storage reservations that not only exhaust host resources but also affect upload capabilities for other users. The issue primarily impacts the default local-storage policy and the default User group. Users are recommended to upgrade to version 4.18.0 to mitigate this risk.

Affected Version(s)

cloudreve < 4.18.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.