What is CVE-2026-55499?
In Cloudreve file management system, authenticated share recipients can access sensitive metadata like file names and paths due to a flaw in the event-stream subscription resolution, leading to unauthorized information disclosure. Organizations should immediately update Cloudreve to the latest version.
Azərbaycanca: Cloudreve fayl idarəetmə sistemində autentifikasiya olunmuş istifadəçi, event-stream mexanizmindəki qüsur səbəbindən fayl yolları, adlar və digər həssas məlumatları əldə edə bilər, bu isə icazəsiz məlumat ifşasına gətirib çıxarır. Təşkilatlar dərhal Cloudreve instansiyalarını son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-200; shared vendor: Cloudreve
FAQ2
Does exploiting CVE-2026-55499 in Cloudreve require authentication?
Yes, the vulnerability can be exploited by an authenticated user. The attacker must be authenticated as a share recipient in the system.
What type of information can be disclosed through CVE-2026-55499?
This vulnerability can lead to unauthorized disclosure of information such as file paths, file names, and other sensitive metadata.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.