๐Ÿ” CVE Alert

CVE-2026-81182

MEDIUM 4.2

SysReptor: Unauthorized file disclosure by broken access control in writable shared notes

CVSS Score
4.2
EPSS Score
0.0%
EPSS Percentile
0th

SysReptor is a fully customizable pentest reporting platform. Prior to 2026.68, an unauthenticated attacker who holds a public read-write note share link can disclose an uploaded file or image from the same project by updating the shared note to reference the target asset filename. The user-controlled reference causes the shared-note authorization logic to treat the asset as permitted, after which the attacker can download it. The attacker must know the asset filename, and the issue does not permit cross-project access. This issue is fixed in version 2026.68.

CWE CWE-639
Vendor syslifters
Product sysreptor
Published Sep 18, 2026
Stay Ahead of the Next One

Get instant alerts for syslifters sysreptor

Be the first to know when new medium vulnerabilities affecting syslifters sysreptor are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

Syslifters / sysreptor
< 2026.68

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/Syslifters/sysreptor/security/advisories/GHSA-x3m3-v8pv-442r github.com: https://github.com/Syslifters/sysreptor/commit/1b721e291ebadfc1457bc8d01f7c70fe5da4b035 github.com: https://github.com/Syslifters/sysreptor/commit/1f3fd629c32560fc4280294f8f9bdc44d97c639a github.com: https://github.com/Syslifters/sysreptor/commit/f730c3acf9ee603f96bb05d598d20f6c4e958eb8 github.com: https://github.com/Syslifters/sysreptor/releases/tag/2026.68