CVE-2026-54544
Last modified
CVE-2026-54544 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. Fireshare facilitates self-hosted media and link sharing. Prior to version 1.6.16, two API endpoints that trigger outbound HTTP requests are missing the @login_required decorator. EPSS estimates a 0.32% chance of exploitation in the next 30 days.
Description
Fireshare facilitates self-hosted media and link sharing. Prior to version 1.6.16, two API endpoints that trigger outbound HTTP requests are missing the @login_required decorator. An unauthenticated attacker can call POST /api/test-discord-webhook or POST /api/test-webhook and cause the Fireshare server to issue an arbitrary HTTP POST to any URL the attacker supplies, including internal network addresses and cloud metadata services. No credentials, session cookies, or prior access are required. Version 1.6.16 contains a patch.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| ShaneIsrael | fireshare | < 1.6.16 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-54544?
How severe is CVE-2026-54544?
How do I fix CVE-2026-54544?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-54538xrdp is an open source RDP server. In versions 0.10.6 and pr…7.5
- CVE-2026-5454A vulnerability was found in GRID Organiser App up to 1.0.5 …3.3
- CVE-2026-54540Pheditor is a single-file editor and file manager written in…8.8
- CVE-2026-54541Nimiq is a Rust implementation of the Nimiq Proof-of-Stake p…3.7
- CVE-2026-54542Nimiq is a Rust implementation of the Nimiq Proof-of-Stake p…3.7
- CVE-2026-54543Froxlor is open source server administration software. Prior…5.4
- CVE-2026-54545wakaru is a JavaScript decompiler and unminifier toolkit. Fr…7.1
- CVE-2026-54546CloudTAK is a browser-based Common Operating Picture and sit…5
- CVE-2026-54547Meta Ads MCP is a Model Context Protocol (MCP) server that l…7.4
- CVE-2026-54548kas is a setup tool for bitbake based projects. Prior to 5.4…3.3
- CVE-2026-54549Meta Ads MCP is a Model Context Protocol (MCP) server that l…8.3
- CVE-2026-5455A vulnerability was determined in Dialogue App up to 4.3.2 o…3.3
Are you affected by CVE-2026-54544?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
