CVE-2026-4831 Details
Description
A security flaw has been discovered in kalcaddle kodbox 1.64. Impacted is the function can of the file /workspace/source-code/app/controller/explorer/auth.class.php of the component Password-protected Share Handler. Performing a manipulation results in improper authentication. The attack is possible to be carried out remotely. The complexity of an attack is rather high. The exploitability is considered difficult. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
An improper authentication vulnerability has been identified in Kalcaddle Kodbox version 1.64. The issue arises in the Password-protected Share Handler, specifically within the 'can' function of 'auth.class.php'. This vulnerability allows authenticated collaborators to bypass folder password requirements when accessing shared folders, enabling direct file downloads from those folders without knowledge of the password. The flaw can be exploited remotely, and a public proof-of-concept exploit is available.
To address this vulnerability, folder password checks should be applied to 'KOD_SHARE_ITEM' paths in the 'can' function. Additionally, folder password enforcement should be centralized to run before all read operations that return file contents, ensuring consistent protection across all relevant endpoints.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Mar 26, 2026CISA-ADP
Assessed Mar 26, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://vuldb.com/?ctiid.353128 | [email protected] | Content Wall |
| https://vuldb.com/?id.353128 | [email protected] | AdvisoryExploitPartial Content |
| https://vuldb.com/?submit.775502 | [email protected] | Technical Description |
| https://vulnplus-note.wetolink.com/share/xdk9igJ3sulk | [email protected] | ExploitRemedyTechnical Analysis |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| kalcaddle kodbox | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Mar 26, 2026 | New CVE Received | [email protected] |
Volerion