Unauthorized File Disclosure in SysReptor by Syslifters
CVE-2026-81182
4.2MEDIUM
What is CVE-2026-81182?
An issue within SysReptor allows an unauthenticated attacker, who possesses a public read-write note share link, to exploit the platform's authorization logic. By modifying the shared note to include a target asset filename, the attacker can gain access to and download uploaded files or images from the associated project. This vulnerability is restricted to the same project and does not facilitate cross-project access. The issue has been resolved in version 2026.68.
Affected Version(s)
sysreptor < 2026.68
