top of page
perceptive_background_267k.jpg

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, POST /api/v4/admin/policy/oauth/signin requires only Admin.Read even though GetO…

Published:

31 juli 2026 om 00:00:00

Alert date:

31 juli 2026 om 07:00:31

Source:

nvd.nist.gov

Click to open the original link from this advisory

Identity & Access, Cloud & Virtualization, Web Technologies

CVE-2026-55502 affects Cloudreve, a self-hosted file management and sharing system, in versions prior to 4.17.0. The vulnerability exists in the POST /api/v4/admin/policy/oauth/signin endpoint, which incorrectly requires only Admin.Read permission instead of Admin.Write. The GetOauthRedirectService handler persists caller-supplied OneDrive secret and app_id values into storage policies without proper authorization checks. This allows an attacker with an OAuth token bearing only Admin.Read privileges to modify OneDrive storage policy credentials, which should require Admin.Write. The flaw stems from the route being inside the admin group with Admin.Read enforcement but lacking the Admin.Write guard applied to sibling policy mutation routes. An attacker could supply malicious secret and app_id values to hijack or manipulate OneDrive storage policy configurations. The issue has been remediated in Cloudreve version 4.17.0.

Technical details

Mitigation steps:

Affected products:

Cloudreve

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page