CVE-2026-33330

FileRise is a self-hosted web file manager / WebDAV server. Prior to version 3.10.0, a broken access control issue in FileRise's ONLYOFFICE integration allows an authenticated user with read-only access to obtain a signed save callbackUrl for a file and then directly forge the ONLYOFFICE save callback to overwrite that file with attacker-controlled content. This issue has been patched in version 3.10.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:filerise:filerise:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:37

Type Values Removed Values Added
Summary
  • (es) FileRise es un gestor de archivos web autoalojado / servidor WebDAV. Antes de la versión 3.10.0, un problema de control de acceso roto en la integración de ONLYOFFICE de FileRise permite a un usuario autenticado con acceso de solo lectura obtener una callbackUrl de guardado firmada para un archivo y luego falsificar directamente la callback de guardado de ONLYOFFICE para sobrescribir ese archivo con contenido controlado por el atacante. Este problema ha sido parcheado en la versión 3.10.0.

26 Mar 2026, 11:58

Type Values Removed Values Added
CPE cpe:2.3:a:filerise:filerise:*:*:*:*:*:*:*:*
First Time Filerise
Filerise filerise
References () https://github.com/error311/FileRise/commit/3871f9fd1661688bed4f7dd23912be0ebf50973c - () https://github.com/error311/FileRise/commit/3871f9fd1661688bed4f7dd23912be0ebf50973c - Patch
References () https://github.com/error311/FileRise/releases/tag/v3.10.0 - () https://github.com/error311/FileRise/releases/tag/v3.10.0 - Product, Release Notes
References () https://github.com/error311/FileRise/security/advisories/GHSA-6c3j-f4x4-36m3 - () https://github.com/error311/FileRise/security/advisories/GHSA-6c3j-f4x4-36m3 - Exploit, Mitigation, Vendor Advisory

24 Mar 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-24 20:16

Updated : 2026-06-17 10:37


NVD link : CVE-2026-33330

Mitre link : CVE-2026-33330

CVE.ORG link : CVE-2026-33330


JSON object : View

Products Affected

filerise

  • filerise
CWE
CWE-863

Incorrect Authorization