Cloudreve: OAuth access tokens bypass scope enforcement due to missing client_id claim
Published Jul 15, 2026
7.6
HIGHCVSS 3.1
EPSS 0.46%
Description
Cloudreve is a self-hosted file management and sharing system. From 4.12.0 until 4.16.1, Cloudreve's OAuth access tokens are issued without the OAuth client_id claim, so the JWT verifier does not load token scopes into request context and RequiredScopes treats the request like non-scoped session authentication, allowing a low-scope OAuth access token to call APIs requiring higher scopes such as file, share, workflow, user setting, WebDAV account, and potentially admin scopes. This issue is fixed in version 4.16.1.
Affected products
-
- Version >= 4.12.0, < 4.16.1StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
github.com/cloudreve/Cloudreve/v4
Go
Introduced 4.0.0-20260114075425-bc6845bd742c Fixed 4.0.0-20260606015557-ed20843dc3dfgithub.com/cloudreve/Cloudreve
Go
Introduced 0 Fixed not fixedgithub.com/cloudreve/Cloudreve/v3
Go
Introduced 0 Fixed not fixed
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/cloudreve/Cloudreve/v4 | 4.0.0-20260114075425-bc6845bd742c | 4.0.0-20260606015557-ed20843dc3df |
| Go | github.com/cloudreve/Cloudreve | 0 | not fixed |
| Go | github.com/cloudreve/Cloudreve/v3 | 0 | not fixed |
Remediation
No remediation recorded yet.
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44689 Advisory
- https://github.com/advisories/GHSA-vgj4-345g-jcf8 Advisory
- https://github.com/cloudreve/cloudreve/commit/ed20843dc3df20a25fcaf6b538647e11c4d68d87 x_refsource_MISC
- https://github.com/cloudreve/cloudreve/releases/tag/4.16.1 x_refsource_MISC
- https://github.com/cloudreve/cloudreve/security/advisories/GHSA-vgj4-345g-jcf8 exploitx_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2026-54560
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44689 | Advisory | |
| https://github.com/advisories/GHSA-vgj4-345g-jcf8 | Advisory | |
| https://github.com/cloudreve/cloudreve/commit/ed20843dc3df20a25fcaf6b538647e11c4d68d87 | x_refsource_MISC | |
| https://github.com/cloudreve/cloudreve/releases/tag/4.16.1 | x_refsource_MISC | |
| https://github.com/cloudreve/cloudreve/security/advisories/GHSA-vgj4-345g-jcf8 | exploitx_refsource_CONFIRM | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-54560 |
Change history (0)
No recorded changes yet.