CVE-2026-91144
Deferred Deferred - Pending Action

ZFile Path Traversal via Share Link Download

Vulnerability report for CVE-2026-91144, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-24

Assigner: VulnCheck

Description

ZFile through 5.0.5 fails to validate requested file paths against a share link's allowed entries on the download endpoint. Attackers holding a share link can supply arbitrary file paths as query parameters to download any file under the shared base directory, bypassing the intended access restrictions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-24
Generated
2026-10-05
AI Q&A
2026-09-15
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

ZFile through version 5.0.5 does not properly validate file paths when users request downloads via share links. Attackers with access to a share link can manipulate query parameters to specify arbitrary file paths, allowing them to download any file within the shared base directory. This bypasses the intended access restrictions meant to limit downloads to only permitted files.

Detection Guidance

This vulnerability allows attackers to bypass access restrictions by supplying arbitrary file paths via query parameters. To detect it, monitor network traffic for unusual file download requests, especially those accessing sensitive paths. Check server logs for requests to the download endpoint with unexpected parameters. No specific commands are provided in the context.

Impact Analysis

If you use ZFile to share files, attackers could exploit this flaw to access sensitive files they are not authorized to view. This could lead to data breaches, unauthorized disclosure of confidential information, or exposure of private user data. The impact depends on the sensitivity of the files stored in the shared directories.

Compliance Impact

This vulnerability could lead to non-compliance with data protection regulations such as GDPR or HIPAA. Unauthorized access to personal or health data may result in violations of confidentiality requirements, potentially leading to legal penalties, fines, or reputational damage for organizations failing to protect sensitive information.

Mitigation Strategies

Upgrade ZFile to a version later than 5.0.5 where path validation is properly enforced on the download endpoint.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-91144. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart