


Perceptive Security
SOC/SIEM Consultancy

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, POST /api/v4/admin/policy/oauth/signin requires only Admin.Read even though GetO…
Published:
31 July 2026 at 00:00:00
Alert date:
31 July 2026 at 07:00:31
Source:
nvd.nist.gov
Identity & Access, Cloud & Virtualization, Web Technologies
CVE-2026-55502 affects Cloudreve, a self-hosted file management and sharing system, in versions prior to 4.17.0. The vulnerability exists in the POST /api/v4/admin/policy/oauth/signin endpoint, which incorrectly requires only Admin.Read permission instead of Admin.Write. The GetOauthRedirectService handler persists caller-supplied OneDrive secret and app_id values into storage policies without proper authorization checks. This allows an attacker with an OAuth token bearing only Admin.Read privileges to modify OneDrive storage policy credentials, which should require Admin.Write. The flaw stems from the route being inside the admin group with Admin.Read enforcement but lacking the Admin.Write guard applied to sibling policy mutation routes. An attacker could supply malicious secret and app_id values to hijack or manipulate OneDrive storage policy configurations. The issue has been remediated in Cloudreve version 4.17.0.
Technical details
Mitigation steps:
Affected products:
Cloudreve
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-55502
https://github.com/cloudreve/cloudreve/security/advisories/GHSA-hq88-5x99-x3gf
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
