What is CVE-2026-55495?
CVE-2026-55495 affects Cloudreve self-hosted file management system. Before version 4.17.0, the WOPI PUT_RELATIVE handler improperly uses the `X-WOPI-SuggestedTarget` header as a path instead of a filename, enabling path traversal via dot-dot-slash segments to write or overwrite files outside the intended directory. Upgrade to Cloudreve 4.17.0 or later immediately.
Azərbaycanca: CVE-2026-55495 Cloudreve fayl idarəetmə sistemində aşkar edilmişdir. 4.17.0 versiyasından əvvəl WOPI PUT_RELATIVE funksiyası `X-WOPI-SuggestedTarget` başlığını səhvən fayl adı deyil, yol kimi qəbul edir, bu da `..` seqmentləri vasitəsilə `Path Traversal` hücumuna və fayl yazmağa imkan verir. Cloudreve-ni dərhal 4.17.0 və ya daha yeni versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
What versions of Cloudreve are affected by CVE-2026-55495?
This vulnerability affects all versions of Cloudreve before version 4.17.0. It is recommended to immediately upgrade to Cloudreve 4.17.0 or later.
Which HTTP header is manipulated in the CVE-2026-55495 vulnerability exploit?
The attacker manipulates the `X-WOPI-SuggestedTarget` header in the WOPI PUT_RELATIVE handler by providing it as a path with dot-dot-slash segments instead of just a filename.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.