CVE-2026-55502High· 7.1▾ TwilightCloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, POST /api/v4/admin/policy/oauth/signin requires only Admin.Read even though GetOauthRedirectService persists caller-supplied OneDrive secret and app_id value…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 31.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.3%
Last analysed / modified upstream
Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, POST /api/v4/admin/policy/oauth/signin requires only Admin.Read even though GetOauthRedirectService persists caller-supplied OneDrive secret and app_id values, allowing an OAuth token without Admin.Write to modify storage policy credentials. The route is inside the admin group that requires Admin.Read, but it does not add the local Admin.Write guard used by sibling policy mutation routes. Its handler persists attacker-supplied secret and app_id values into the selected OneDrive storage policy before returning an OAuth URL. This issue is fixed in version 4.17.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
github.com/cloudreve/Cloudreve/v4 < 4.0.0-20260613030954-9e9fb43e7288github.com/cloudreve/Cloudreve/v3 <= 3.0.0-20250225100611-da4e44b77af4Patched in:
github.com/cloudreve/Cloudreve/v4 4.17.0Connected by shared product, vendor, weakness, or advisory.
GHSA-v6w6-358x-2433Medium· 5.4Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests
CVE-2026-55499Medium· 4.3Cloudreve is a self-hosted file management and sharing system
CVE-2026-62323Medium· 6.3Cloudreve is a self-hosted file management and sharing system
CVE-2026-54563High· 7.1Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root
GHSA-vx2m-jpxr-xv7wMedium· 5.3Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint
CVE-2026-55495Medium· 4.3Cloudreve is a self-hosted file management and sharing system