VYPR
High severity7.5NVD Advisory· Published Sep 14, 2026

CVE-2026-91144

CVE-2026-91144

Description

ZFile through 5.0.5 fails to validate requested file paths against a share link's allowed entries on the download endpoint. Attackers holding a share link can supply arbitrary file paths as query parameters to download any file under the shared base directory, bypassing the intended access restrictions.

Affected products

2
  • Zfile Dev/Zfilereferences2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: <=5.0.5

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.