Privilege Escalation Vulnerability in FileRise by Error311
CVE-2026-92616
7.6HIGH
What is CVE-2026-92616?
FileRise prior to version 3.28.0 is susceptible to a vulnerability that allows low-privilege authenticated users to escalate their privileges. This is achieved by exploiting a flaw in session isolation between the WebDAV interface and the web application session context. Attackers can utilize their valid Basic-Auth credentials alongside an active admin PHPSESSID cookie to gain unauthorized read and write access, effectively bypassing established authorization boundaries. The vulnerability arises because the WebDAV layer incorrectly inherits elevated privileges from an ambient web session rather than implementing independent stateless authentication, as stipulated in RFC 4918.
Affected Version(s)
FileRise 0 < 3.28.0
