---
id: CVE-2026-82582
title: >-
  An authorization bypass vulnerability exists in SHIRASAGI through a
  user-controlled key, which may allow an unauthorized attacker to retrieve
  files from the groupware's shared file feature.
summary: >-
  An authorization bypass vulnerability exists in SHIRASAGI through a
  user-controlled key, which may allow an unauthorized attacker to retrieve
  files from the groupware's shared file feature.
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-639
vendor: SHIRASAGI Project
product: SHIRASAGI
affected:
  - SHIRASAGI <= v1.20.2
published: '2026-09-10'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T15:13:07.090'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82582'
references:
  - url: 'https://jvn.jp/en/jp/JVN37476837/'
    label: vultures@jpcert.or.jp
  - url: 'https://www.ss-proj.org/support/1710.html'
    label: vultures@jpcert.or.jp
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-10T12:58:39.791596Z'
ingestedAt: '2026-09-10T06:34:51.924Z'
epss: 0.00307
epssPercentile: 0.21022
---

## Overview

An authorization bypass vulnerability exists in SHIRASAGI through a user-controlled key, which may allow an unauthorized attacker to retrieve files from the groupware's shared file feature.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
