๐Ÿ” CVE Alert

CVE-2026-92616

MEDIUM 6.8

FileRise < 3.28.0 Privilege Escalation via WebDAV Session Inheritance

CVSS Score
6.8
EPSS Score
0.0%
EPSS Percentile
0th

FileRise before version 3.28.0 contains a privilege escalation vulnerability that allows authenticated low-privilege attackers to gain unauthorized read and write access by exploiting improper session isolation between the WebDAV interface and the web application session context. Attackers can combine valid Basic-Auth credentials with an active admin PHPSESSID cookie to bypass authorization boundaries, as the WebDAV layer incorrectly inherits elevated privileges from an ambient web session rather than enforcing independent stateless authentication per RFC 4918.

CWE CWE-613
Vendor error311
Product filerise
Published Sep 16, 2026
Last Updated Sep 16, 2026
Stay Ahead of the Next One

Get instant alerts for error311 filerise

Be the first to know when new medium vulnerabilities affecting error311 filerise are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

error311 / FileRise
0 < 3.28.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/error311/FileRise/releases/tag/v3.28.0 vulncheck.com: https://www.vulncheck.com/advisories/filerise-privilege-escalation-via-webdav-session-inheritance

Credits

Lazizbek Djurayev (Haad TC) VulnCheck