{"id":"CVE-2026-62323","aliases":["GHSA-c3jm-gv5r-9wcp","GO-2026-6104"],"url":"https://o3.security/vulnerability/CVE-2026-62323","summary":"Cloudreve: Unauthorized file write via WOPI view sessions whose access token secret is ignored","details":"Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, ViewerSessionValidation uses only the session-id prefix of a WOPI access token and does not enforce the requested viewer action, allowing a malicious or compromised WOPI viewer with a view session to forge the token suffix and invoke WOPI write routes for the underlying file. This issue is fixed in version 4.17.0.","published":"2026-07-31T03:43:14.900Z","modified":"2026-08-18T15:10:31.897290685Z","cvss":{"score":6.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:N"},"epss":{"score":0.00171,"percentile":0.06662,"asOf":"2026-09-06"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/cloudreve/Cloudreve/v4","fixedVersion":"4.0.0-20260626022433-f3347130ac48"},{"ecosystem":"Go","name":"github.com/cloudreve/Cloudreve/v3","fixedVersion":null}],"fix":{"url":"https://github.com/cloudreve/cloudreve/commit/f3347130ac48f2ff996af9ef66c97be2dda9cba9","label":"cloudreve/cloudreve@f334713"},"references":[{"type":"WEB","url":"https://github.com/cloudreve/cloudreve/releases/tag/4.17.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/62xxx/CVE-2026-62323.json"},{"type":"ADVISORY","url":"https://github.com/cloudreve/cloudreve/security/advisories/GHSA-c3jm-gv5r-9wcp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-62323"},{"type":"FIX","url":"https://github.com/cloudreve/cloudreve/commit/f3347130ac48f2ff996af9ef66c97be2dda9cba9"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-18T15:10:31.897290685Z"}}