CVE-2026-56768 Details
Description
Seahub before 13.0.23 does not enforce SHARE_LINK_LOGIN_REQUIRED on GET /api/v2.1/share-link-zip-task/, allowing unauthenticated users to bypass authentication. Attackers with a folder share-link token can call the GET endpoint to obtain a fileserver zip token and download entire shared directory trees.
A vulnerability exists in Seafile Seahub versions prior to 13.0.23, where the SHARE_LINK_LOGIN_REQUIRED directive is not enforced on the GET /api/v2.1/share-link-zip-task/ endpoint. This oversight allows unauthenticated users to bypass authentication. Attackers possessing a folder share-link token can exploit this vulnerability to obtain a fileserver zip token, enabling them to download entire shared directory trees.
Users can upgrade to Seafile Seahub version 13.0.23 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 25, 2026CISA-ADP
Assessed Jun 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/haiwen/seahub/commit/162cddae0831188d02bb8d451dc2193e197dcc57 | [email protected] | Source CodeVendor |
| https://github.com/haiwen/seahub/commit/b609949cf64ed6a15708d0fb5ea9c179962e23cc | [email protected] | Source CodeVendor |
| https://github.com/haiwen/seahub/issues/9050 | [email protected] | Issue TrackingVendor |
| https://plus.seafile.com/wiki/publish/seafile-wiki/v5D5/ | [email protected] | Release NotesVendor |
| https://www.vulncheck.com/advisories/seahub-authentication-bypass-in-sharelinkziptaskview-get-method | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Haiwen Seahub | < 13.0.23 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 14, 2026 | CVE Modified | [email protected] |
| Jun 30, 2026 | CVE Modified | CISA-ADP |
| Jun 25, 2026 | New CVE Received | [email protected] |
Volerion