Privilege Escalation Vulnerability in FileRise by Error311
CVE-2026-92616

7.6HIGH

Key Information:

Vendor

Error311

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-92616?

FileRise prior to version 3.28.0 is susceptible to a vulnerability that allows low-privilege authenticated users to escalate their privileges. This is achieved by exploiting a flaw in session isolation between the WebDAV interface and the web application session context. Attackers can utilize their valid Basic-Auth credentials alongside an active admin PHPSESSID cookie to gain unauthorized read and write access, effectively bypassing established authorization boundaries. The vulnerability arises because the WebDAV layer incorrectly inherits elevated privileges from an ambient web session rather than implementing independent stateless authentication, as stipulated in RFC 4918.

Affected Version(s)

FileRise 0 < 3.28.0

References

CVSS V4

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lazizbek Djurayev (Haad TC)
VulnCheck
.