CVE-2026-55499
Received Received - Intake

Cloudreve Prior to 4.17.0 Path Traversal in Share Event-Stream

Vulnerability report for CVE-2026-55499, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-31

Last updated on: 2026-07-31

Assigner: GitHub, Inc.

Description

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, a single-file share event-stream subscription resolves the share root to the owner’s parent folder and subscribes to that folder topic, allowing an authenticated share recipient to receive names, paths, rename targets, event types, and hashed identifiers for unshared sibling files and folders. This issue is fixed in version 4.17.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-31
Last Modified
2026-07-31
Generated
2026-07-31
AI Q&A
2026-07-31
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
cloudreve cloudreve 4.17.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Cloudreve before version 4.17.0 has a vulnerability where a single-file share event-stream subscription incorrectly resolves the share root to the owner's parent folder. This allows an authenticated share recipient to subscribe to that folder's topic and receive sensitive information about unshared sibling files and folders, including names, paths, rename targets, event types, and hashed identifiers.

Detection Guidance

To detect this vulnerability, monitor Cloudreve event streams for unauthorized access to sibling file metadata. Check logs for event subscriptions to single-file shares that resolve to parent folders. Verify if recipients receive events for unshared files by inspecting the HandleExplorerEventsPush function behavior in service/explorer/events.go.

Impact Analysis

If you use Cloudreve versions before 4.17.0, an attacker with access to a shared file could potentially gain visibility into other files and folders on your system that they should not be able to see. This could lead to unauthorized information disclosure about your file structure and operations.

Compliance Impact

This vulnerability could potentially affect compliance with GDPR and HIPAA by exposing metadata of unshared files to unauthorized users. GDPR requires protection of personal data, and unauthorized access to file paths or identifiers may constitute a breach. HIPAA mandates safeguards for protected health information, and metadata exposure could risk compliance if such data is involved.

Mitigation Strategies

Upgrade Cloudreve to version 4.17.0 or later to address the vulnerability. Ensure all instances are updated to prevent unauthorized access to file metadata and paths.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-55499. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart