CVE-2026-33330

FileRise is a self-hosted web file manager / WebDAV server. Prior to version 3.10.0, a broken access control issue in FileRise's ONLYOFFICE integration allows an authenticated user with read-only access to obtain a signed save callbackUrl for a file and then directly forge the ONLYOFFICE save callback to overwrite that file with attacker-controlled content. This issue has been patched in version 3.10.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:filerise:filerise:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-03-24 20:16

Updated : 2026-03-26 11:58


NVD link : CVE-2026-33330

Mitre link : CVE-2026-33330

CVE.ORG link : CVE-2026-33330


JSON object : View

Products Affected

filerise

  • filerise
CWE
CWE-863

Incorrect Authorization