CVE-2026-107781
Deferred Deferred - Pending Action

Server-Side Request Forgery in Dromara Skyeye

Vulnerability report for CVE-2026-107781, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: VulnCheck

Description

Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains a server-side request forgery and missing authorization vulnerability in the OnlyOffice save callback editUploadOfficeFileById. Unauthenticated attackers can supply arbitrary url and key parameters to make the server fetch internal URLs and overwrite any user's stored file, then read results via queryFileToShowById.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
dromara skyeye 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Dromara Skyeye allows unauthenticated attackers to perform server-side request forgery and bypass authorization checks. By manipulating the OnlyOffice save callback function editUploadOfficeFileById, attackers can supply arbitrary URL and key parameters to force the server to fetch internal URLs and overwrite any user's stored files. They can then read the results via queryFileToShowById.

Detection Guidance

To detect this vulnerability, inspect network traffic for unauthorized requests to internal URLs via the OnlyOffice save callback endpoint. Check logs for editUploadOfficeFileById calls with arbitrary url and key parameters. Verify if file overwrites or unauthorized file reads occur through queryFileToShowById.

Impact Analysis

This vulnerability can lead to unauthorized file access, data theft, or data corruption. Attackers could overwrite critical files, steal sensitive information, or disrupt operations by modifying stored documents. The impact depends on the server's configuration and the files it processes.

Compliance Impact

This vulnerability could violate compliance requirements by enabling unauthorized access to sensitive data, leading to potential breaches of GDPR, HIPAA, or other regulations. Organizations may face legal penalties, reputational damage, and loss of trust due to compromised data integrity and confidentiality.

Mitigation Strategies

Immediately update Dromara Skyeye to the latest version to patch the vulnerability. Disable the OnlyOffice integration if not required. Restrict network access to the server to prevent unauthorized requests. Monitor for unusual file access or modifications.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107781. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart