CVE ID :CVE-2026-91144
Published : Sept. 14, 2026, 10:16 p.m. | 1 hour, 1 minute ago
Description :ZFile through 5.0.5 fails to validate requested file paths against a share link’s allowed entries on the download endpoint. Attackers holding a share link can supply arbitrary file paths as query parameters to download any file under the shared base directory, bypassing the intended access restrictions.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more…
Published : Sept. 14, 2026, 10:16 p.m. | 1 hour, 1 minute ago
Description :ZFile through 5.0.5 fails to validate requested file paths against a share link’s allowed entries on the download endpoint. Attackers holding a share link can supply arbitrary file paths as query parameters to download any file under the shared base directory, bypassing the intended access restrictions.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more…