What is CVE-2026-62323?
CVE-2026-62323 in Cloudreve allows a malicious WOPI viewer to forge tokens by exploiting incomplete validation of the session-id prefix without enforcing the requested viewer action. This affects versions prior to 4.17.0, and upgrading is required to mitigate the risk.
Azərbaycanca: Cloudreve fayl idarəetmə sistemində aşkar edilmiş CVE-2026-62323 zəifliyi WOPI access token sessiyasının yalnız prefiksini yoxlayır və tələb olunan əməliyyatı məhdudlaşdırmır. Bu, zərərli WOPI viewer-in yalnız baxış sessiyası ilə token-i saxtalaşdırmasına səbəb olur. 4.17.0 versiyasına qədər təsir edir, ona görə də dərhal yenilənmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
What is the root cause of CVE-2026-62323 in Cloudreve?
The vulnerability exists because the WOPI access token session only validates the prefix without restricting the requested viewer action, allowing a malicious WOPI viewer to forge tokens using only a view session.
What action is required to mitigate CVE-2026-62323?
Since the vulnerability affects all versions prior to 4.17.0, upgrading immediately is required to mitigate the risk.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.