What is CVE-2026-54719?
CVE-2026-54719 is a vulnerability in goshs file server versions prior to 2.1.1, where the 'bulkDownload' handler skips ACL and custom authentication checks. This allows unauthenticated read access to files protected only by .goshs folder ACLs. Users should upgrade to version 2.1.1 or later immediately.
Azərbaycanca: CVE-2026-54719, goshs fayl serverinin 2.1.1 versiyasından əvvəlki versiyalarında 'bulkDownload' funksiyasında identifikasiya yoxlamasının edilməməsi səbəbindən yaranan boşluqdur. Bu zəiflik, yalnız .goshs qovluq ACL-ləri ilə qorunan faylların autentifikasiya olmadan oxunmasına imkan verir. İstifadəçilərə dərhal 2.1.1 və ya daha yuxarı versiyaya yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
Which function in goshs file server is affected by CVE-2026-54719?
The vulnerability exists in the 'bulkDownload' handler due to missing authentication checks.
How can users protect themselves against CVE-2026-54719?
Users should immediately upgrade goshs file server to version 2.1.1 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.