CVE-2026-100727
Received Received - Intake

Improper Access Control in GROWI via Local File Upload

Vulnerability report for CVE-2026-100727, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: JPCERT/CC

Description

An improper access control vulnerability exists in GROWI, which allow an unauthenticated attacker to read files contained in non-public pages of the affected product when the file upload setting is configured as "Local".

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
growi growi *
growi_inc growi to 7.5.5 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-552 The product makes files or directories accessible to unauthorized actors, even though they should not be.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an improper access control issue in GROWI versions before v7.5.5 when file uploads are set to 'Local'. It allows unauthenticated attackers to read files in non-public pages without proper authorization. The flaw exists because files are stored in a static file delivery area without necessary access controls or response headers.

Detection Guidance

Check if GROWI is running a version prior to v7.5.5 by inspecting the version in the application or server logs. Verify if the file upload setting is configured as 'Local' in the GROWI admin panel. Test direct access to uploaded files by attempting to access URLs like /uploads/filename without authentication.

Impact Analysis

An attacker could access sensitive files such as non-public page attachments, user images, page exports, or audit log exports. This may lead to data leaks, unauthorized information disclosure, or potential further attacks if the exposed files contain exploitable content.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR (data protection) and HIPAA (health information privacy) by exposing sensitive or personal data to unauthorized parties. Organizations using affected GROWI versions may face regulatory penalties, legal liabilities, and reputational damage due to data breaches.

Mitigation Strategies

Immediately update GROWI to version v7.5.5 or later. If using 'Local' file upload, consider switching to cloud storage like Amazon S3, GCS, or Azure Blob Storage to avoid exposure. Ensure no sensitive files are accessible via direct URL access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-100727. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart