CVE-2026-108582
Received Received - Intake

Incorrect Permissions in GenOffice HTTP MCP Server Allow Unauthorized Document Access

Vulnerability report for CVE-2026-108582, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: VulnCheck

Description

GenOffice through 0.11.505 contains an incorrect permissions vulnerability in its HTTP MCP server file store that allows local unprivileged users to read uploaded and generated documents. Attackers can list the world-readable genoffice-mcp-http directory under the system temporary directory to read client uploads and converted outputs, bypassing the HTTP bearer token.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
genspark-ai GenOffice 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-732 The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

GenOffice through version 0.11.505 has an insecure permissions flaw in its HTTP MCP server file store. The application creates a world-readable temporary directory under /tmp on POSIX systems to store uploaded and generated documents. Files and directories are created with default permissions (0755 for directories and 0644 for files), making them accessible to all local users. This bypasses the HTTP bearer token security, allowing unauthorized access to sensitive documents without authentication.

Detection Guidance

Check the genoffice-mcp-http directory under /tmp for world-readable permissions. Use commands like 'ls -ld /tmp/genoffice-mcp-http' to verify directory permissions and 'find /tmp/genoffice-mcp-http -type f -perm -o+r -ls' to list readable files.

Impact Analysis

If you use GenOffice on a shared system, any local user can read your uploaded or generated documents by accessing the genoffice-mcp-http directory in the system temporary folder. This includes sensitive files like PDFs, spreadsheets, or other documents processed by the application. The attack requires no special privileges beyond local system access.

Compliance Impact

This vulnerability likely violates compliance requirements for data protection standards such as GDPR and HIPAA, which mandate strict controls over sensitive data access. Unauthorized local access to documents could result in data breaches, leading to potential legal penalties, reputational damage, and loss of trust. Organizations must ensure proper file permissions to meet regulatory obligations.

Mitigation Strategies

Set restrictive permissions on the genoffice-mcp-http directory using 'chmod 700 /tmp/genoffice-mcp-http' and files with 'chmod 600'. Alternatively, restrict /tmp access or use an owner-only temporary directory.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108582. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart