File Management and Sharing Vulnerability in Cloudreve by Cloudreve
CVE-2026-77633
7.1HIGH
What is CVE-2026-77633?
In Cloudreve, a self-hosted file management and sharing system, users prior to version 4.18.0 can exploit a flaw in the PrepareUpload function. This flaw allows authenticated users with Files.Write permissions to bypass storage limits by manipulating upload-session requests. The vulnerability enables concurrent requests that can exceed the user's declared storage capacity, resulting in excessive storage reservations that not only exhaust host resources but also affect upload capabilities for other users. The issue primarily impacts the default local-storage policy and the default User group. Users are recommended to upgrade to version 4.18.0 to mitigate this risk.
Affected Version(s)
cloudreve < 4.18.0
