ZFile through 5.0.5 fails to validate requested file paths against a share link's allowed entries on the download endpoint. Attackers holding a share link can supply arbitrary file paths as query parameters to download any file under the shared base directory, bypassing the intended access restrictions.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-14 22:16
Updated : 2026-09-14 22:16
NVD link : CVE-2026-91144
Mitre link : CVE-2026-91144
CVE.ORG link : CVE-2026-91144
JSON object : View
Products Affected
No product.
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
