Unauthorized File Disclosure in SysReptor by Syslifters
CVE-2026-81182

4.2MEDIUM

Key Information:

Vendor

Syslifters

Status
Vendor
CVE Published:
18 September 2026

What is CVE-2026-81182?

An issue within SysReptor allows an unauthenticated attacker, who possesses a public read-write note share link, to exploit the platform's authorization logic. By modifying the shared note to include a target asset filename, the attacker can gain access to and download uploaded files or images from the associated project. This vulnerability is restricted to the same project and does not facilitate cross-project access. The issue has been resolved in version 2026.68.

Affected Version(s)

sysreptor < 2026.68

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.