CVE-2026-92616
FileRise < 3.28.0 Privilege Escalation via WebDAV Session Inheritance
CVSS Score
6.8
EPSS Score
0.0%
EPSS Percentile
0th
FileRise before version 3.28.0 contains a privilege escalation vulnerability that allows authenticated low-privilege attackers to gain unauthorized read and write access by exploiting improper session isolation between the WebDAV interface and the web application session context. Attackers can combine valid Basic-Auth credentials with an active admin PHPSESSID cookie to bypass authorization boundaries, as the WebDAV layer incorrectly inherits elevated privileges from an ambient web session rather than enforcing independent stateless authentication per RFC 4918.
| CWE | CWE-613 |
| Vendor | error311 |
| Product | filerise |
| Published | Sep 16, 2026 |
| Last Updated | Sep 16, 2026 |
Stay Ahead of the Next One
Get instant alerts for error311 filerise
Be the first to know when new medium vulnerabilities affecting error311 filerise are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
Affected Versions
error311 / FileRise
0 < 3.28.0
References
Credits
Lazizbek Djurayev (Haad TC) VulnCheck