Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 14 Sep 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ZFile through 5.0.5 fails to validate requested file paths against a share link's allowed entries on the download endpoint. Attackers holding a share link can supply arbitrary file paths as query parameters to download any file under the shared base directory, bypassing the intended access restrictions. | |
| Title | ZFile through 5.0.5 Share Entry Filter Bypass via Download Endpoint | |
| First Time appeared |
Zfile
Zfile zfile |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:zfile:zfile:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Zfile
Zfile zfile |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-14T21:45:44.595Z
Reserved: 2026-09-14T20:35:39.547Z
Link: CVE-2026-91144
No data.
Status : Received
Published: 2026-09-14T22:16:59.053
Modified: 2026-09-14T22:16:59.053
Link: CVE-2026-91144
No data.
OpenCVE Enrichment
No data.
-
CWE-639
Authorization Bypass Through User-Controlled Key