CVE-2026-77637
Last modified
CVE-2026-77637 is a low-severity vulnerability rated 3.8/10 on the CVSS scale. Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, tool.GET("wopi") and tool.POST("mail") in routers/router.go inherit ScopeAdminRead but omit the RequiredScopes(types.ScopeAdminWrite) middleware applied to neighboring state-changing admin tool routes.
Description
Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, tool.GET("wopi") and tool.POST("mail") in routers/router.go inherit ScopeAdminRead but omit the RequiredScopes(types.ScopeAdminWrite) middleware applied to neighboring state-changing admin tool routes. An OAuth application or API key limited to Admin.Read can therefore probe configured WOPI service endpoints and send arbitrary test email through the server SMTP configuration, exceeding the token's intended read-only authorization boundary. This issue is fixed in version 4.18.0.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-77637?
How severe is CVE-2026-77637?
How do I fix CVE-2026-77637?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-77620Vector is a high-performance observability data pipeline. Fr…8.7
- CVE-2026-77621Vector is a high-performance observability data pipeline. Fr…9.3
- CVE-2026-7763A heap-based buffer overflow vulnerability in the morse.ko H…9.8
- CVE-2026-77633Cloudreve is a self-hosted file management and sharing syste…7.1
- CVE-2026-77634CakePHP is a rapid development framework for PHP. Prior to v…8.2
- CVE-2026-77635CakePHP is a rapid development framework for PHP. Prior to v…9.2
- CVE-2026-77638Tor before 0.4.9.11 is prone to a race condition where in ju…9
- CVE-2026-77639Tor before 0.4.9.9 was prone to a compression bomb bypass wh…5.3
- CVE-2026-7764An out-of-bounds read vulnerability in the morse.ko HaLow Wi…6.8
- CVE-2026-77640tor before 0.4.9.9 was prone to an infinite loop when decomp…5.3
- CVE-2026-77641tor before 0.4.9.9 was prone to a NULL write after free when…8.2
- CVE-2026-77642tor before 0.4.9.9 was prone to an out-of-bounds write when …9.3
Are you affected by CVE-2026-77637?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
