What is CVE-2026-55496?
CVE-2026-55496 is a vulnerability in Cloudreve file management system before version 4.17.0. It allows any logged-in user to enumerate email addresses and profile metadata of inactive users via the /api/v4/user/search endpoint. Upgrading to version 4.17.0 or later is recommended.
Azərbaycanca: CVE-2026-55496 Cloudreve fayl idarəetmə sistemində aşkarlanmış bir boşluqdur. 4.17.0 versiyasından əvvəlki versiyalarda, aktiv olmayan istifadəçilərin e-poçt ünvanlarını və profil məlumatlarını icazəsiz əldə etməyə imkan verir. 4.17.0 və ya daha yeni versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200; shared vendor: Cloudreve
FAQ2
Which versions of Cloudreve are affected by CVE-2026-55496?
This vulnerability affects Cloudreve file management system versions prior to 4.17.0.
What information can be exposed through CVE-2026-55496?
Any logged-in user can unauthorizedly access email addresses and profile metadata of inactive users.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.