CVE-2026-33330 Details
Description
FileRise is a self-hosted web file manager / WebDAV server. Prior to version 3.10.0, a broken access control issue in FileRise's ONLYOFFICE integration allows an authenticated user with read-only access to obtain a signed save callbackUrl for a file and then directly forge the ONLYOFFICE save callback to overwrite that file with attacker-controlled content. This issue has been patched in version 3.10.0.
A broken access control vulnerability has been identified in FileRise, a self-hosted web file manager and WebDAV server, prior to version 3.10.0. The issue arises in the ONLYOFFICE integration, where an authenticated user with read-only access can obtain a signed save callback URL for a file. This URL can be forged to overwrite the file with content controlled by the attacker. The vulnerability exists because the ONLYOFFICE callback handler trusts user-supplied data to authorize write operations, allowing unauthorized modifications to files.
Users can update to FileRise version 3.10.0, which addresses this vulnerability by tightening the authorization process for ONLYOFFICE callbacks. Instructions for downloading the latest version are available on the FileRise GitHub releases page.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/error311/FileRise/commit/3871f9fd1661688bed4f7dd23912be0ebf50973c | [email protected] | Patch |
| https://github.com/error311/FileRise/releases/tag/v3.10.0 | [email protected] | ProductRelease Notes |
| https://github.com/error311/FileRise/security/advisories/GHSA-6c3j-f4x4-36m3 | [email protected] | ExploitMitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| filerise filerise | < 3.10.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 26, 2026 | Initial Analysis | [email protected] |
| Mar 24, 2026 | New CVE Received | [email protected] |