๐Ÿ” CVE Alert

CVE-2026-44460

HIGH 7.4

FileRise: TOTP Bypass via Setup Endpoint Disclosing Existing Secret

CVSS Score
7.4
EPSS Score
0.0%
EPSS Percentile
9th

FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. Prior to 3.12.0, /api/totp_setup.php is callable from a session that has only passed the password check (state pending_login_user). When the target account already has TOTP configured, the endpoint decrypts and returns the user's existing TOTP secret inside the QR PNG instead of refusing or generating a new secret. An attacker who already possesses the victim's password can therefore retrieve the live TOTP secret, derive a valid one-time code, submit it to /api/totp_verify.php, and obtain a fully authenticated session without ever possessing the victim's authenticator device. This vulnerability is fixed in 3.12.0.

CWE CWE-200 CWE-287 CWE-306
Vendor error311
Product filerise
Published May 27, 2026
Last Updated May 28, 2026
Stay Ahead of the Next One

Get instant alerts for error311 filerise

Be the first to know when new high vulnerabilities affecting error311 filerise are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

error311 / FileRise
< 3.12.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/error311/FileRise/security/advisories/GHSA-84hw-8g73-v3f8