Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-92616— FileRise < 3.28.0 Privilege Escalation via WebDAV Session Inheritance

Quick assessment

Affected
error311 FileRise
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

FileRise 3.28.0 之前的版本存在一个权限提升漏洞,该漏洞允许已认证的较低权限攻击者通过利用 WebDAV 接口与 Web 应用会话上下文之间不当的会话隔离,获得未经授权的读取和写入访问权限。攻击者可以将有效的 Basic-Auth 凭据与一个处于激活状态的管理员 PHPSESSID Cookie 相结合,从而绕过授权边界。这是因为 WebDAV 层错误地从周围(ambient)Web 会话中继承了提升后的权限,而不是按照 RFC 4918 的要求,为每个请求执行独立的、无状态的认证。

CVSS 6.8 · Medium

Affected Version Matrix 1

VendorProduct Version RangeStatus
error311 FileRise < 3.28.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-92616

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
FileRise < 3.28.0 Privilege Escalation via WebDAV Session Inheritance
Source: CVE Program / CVE List V5
Vulnerability Description
FileRise before version 3.28.0 contains a privilege escalation vulnerability that allows authenticated low-privilege attackers to gain unauthorized read and write access by exploiting improper session isolation between the WebDAV interface and the web application session context. Attackers can combine valid Basic-Auth credentials with an active admin PHPSESSID cookie to bypass authorization boundaries, as the WebDAV layer incorrectly inherits elevated privileges from an ambient web session rather than enforcing independent stateless authentication per RFC 4918.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
不充分的会话过期机制
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
error311 FileRise 0 ~ 3.28.0 -

II. Public POCs for CVE-2026-92616

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-92616

登录查看更多情报信息。

Vendor Advisories for CVE-2026-92616 (1)

Vendor Pages for CVE-2026-92616 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-92616

No comments yet


Leave a comment