Skip to content

Cloudreve vulnerabilities

3 CVEs tracked

Cloudreve appears in our threat intelligence reporting as a self-hosted file management system with critical vulnerabilities prior to version 4.17.0. The main theme is insufficient permission enforcement allowing authenticated users to perform sensitive actions, such as obtaining an OAuth token with only Admin.Read privileges (CVE-2026-55502) and misconfigured event-stream subscriptions exposing metadata (CVE-2026-55499). Defenders should also pay close attention to an information disclosure vulnerability allowing email enumeration (CVE-2026-55496) and prioritize immediate patching to version 4.17.0.

Azərbaycanca: Cloudreve öz host edilən fayl idarəetmə sistemi olaraq bizim raportlarımızda 4.17.0 versiyasından əvvəlki kritik boşluqlarla bağlı görünür. Başlıca hadisə, autentifikasiya olunmuş istifadəçilərin yetərli icazələr olmadan həssas əməliyyatlar icra edə bilməsi ilə bağlıdır; məsələn, Admin.Read icazəsi ilə OAuth token əldə oluna bilməsi (CVE-2026-55502) və timestamp əhatə dairəsinin səhv konfiqurasiyası (CVE-2026-55499). Müdafiəçi eyni zamanda e-poçt ünvanlarının sadalanmasına imkan verən məlumat sızması zəifliyinə (CVE-2026-55496) diqqət yetirməli və sistemin təcili olaraq 4.17.0 versiyasına yenilənməsini təmin etməlidir.

This vendor's CVEs3

This hub is built from skopnix's own reporting on Cloudreve: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.