{"id":"CVE-2026-54560","aliases":["GHSA-vgj4-345g-jcf8","GO-2026-6022"],"url":"https://o3.security/vulnerability/CVE-2026-54560","summary":"Cloudreve: OAuth access tokens bypass scope enforcement due to missing client_id claim","details":"Cloudreve is a self-hosted file management and sharing system. From 4.12.0 until 4.16.1, Cloudreve's OAuth access tokens are issued without the OAuth client_id claim, so the JWT verifier does not load token scopes into request context and RequiredScopes treats the request like non-scoped session authentication, allowing a low-scope OAuth access token to call APIs requiring higher scopes such as file, share, workflow, user setting, WebDAV account, and potentially admin scopes. This issue is fixed in version 4.16.1.","published":"2026-07-15T14:40:24.765Z","modified":"2026-08-12T03:51:26.696389739Z","cvss":{"score":7.6,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L"},"epss":{"score":0.00463,"percentile":0.38116,"asOf":"2026-08-25"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/cloudreve/Cloudreve/v4","fixedVersion":"4.0.0-20260606015557-ed20843dc3df"}],"fix":{"url":"https://github.com/cloudreve/cloudreve/commit/ed20843dc3df20a25fcaf6b538647e11c4d68d87","label":"cloudreve/cloudreve@ed20843"},"references":[{"type":"WEB","url":"https://github.com/cloudreve/cloudreve/releases/tag/4.16.1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54560.json"},{"type":"ADVISORY","url":"https://github.com/cloudreve/cloudreve/security/advisories/GHSA-vgj4-345g-jcf8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54560"},{"type":"FIX","url":"https://github.com/cloudreve/cloudreve/commit/ed20843dc3df20a25fcaf6b538647e11c4d68d87"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:26.696389739Z"}}