


Perceptive Security
SOC/SIEM Consultancy

FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. Prior to 3.12.0, /api/totp_setup.php is callable from a …
Published:
26 mei 2026 om 22:00:00
Alert date:
27 mei 2026 om 19:08:13
Source:
nvd.nist.gov
Web Technologies, Identity & Access
FileRise, a self-hosted web-based file manager, has a critical vulnerability in versions prior to 3.12.0. The /api/totp_setup.php endpoint improperly handles TOTP configuration requests from sessions that have only passed password authentication. When a user account already has TOTP configured, the endpoint incorrectly decrypts and returns the existing TOTP secret within a QR PNG response. This allows attackers who possess a victim's password to extract the live TOTP secret, generate valid one-time codes, and bypass two-factor authentication to gain full session access without physical access to the victim's authenticator device. The vulnerability represents a complete bypass of multi-factor authentication protections and has been fixed in version 3.12.0.
Technical details
Mitigation steps:
Affected products:
FileRise
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-44460
https://github.com/error311/FileRise/security/advisories/GHSA-84hw-8g73-v3f8
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
