Back

MEDIUM

FileRise has incorrect authorization in /api/file/snippet.php allows read_own users to read other users’ file content

Published Mar 26, 2026

Description

FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. In versiosn 2.3.7 through 3.10.0, the file snippet endpoint `/api/file/snippet.php` allows an authenticated user with only `read_own` access to a folder to retrieve snippet content from files uploaded by other users in the same folder. This is a server-side authorization flaw in the `read_own` enforcement for hover previews. Version 3.11.0 fixes the issue.

Affected products

Remediation

No remediation recorded yet.

References (3)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner GitHub_M
Published Mar 26, 2026
Updated Mar 26, 2026
Reserved Mar 20, 2026

CISA Vulnrichment

Updated Mar 26, 2026

NVD

Status Analyzed
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner GitHub_M
Published Mar 26, 2026
Updated Mar 26, 2026

GitHub

No data