Skip to main content
EPSS 0.4%top 71%

CVE-2026-76032: Missing Authorization in pydio cells

0
Medium
VulnerabilityCVE-2026-76032cvecve-2026-76032
Published: 08/18/2026 (08/18/2026, 19:49:48 UTC)
Source: CVE Database V5
Vendor/Project: pydio
Product: cells

Description

Pydio Cells 5.0.0 through 5.0.2 returns share-link details to any authenticated user. The REST handler for GET /a/share/link/{Uuid} in idm/share/rest/handler.go reads the workspace UUID from the path, calls LinkById, and writes the result with no authorization step, whereas the sibling handler for GET /a/share/cell/{Uuid} loads the workspace and requires MatchPolicies with ResourcePolicyAction_READ, returning a not-found error so that existence is not disclosed. Nothing compensates further down: GetLinkWorkspace reaches GetOrCreateWorkspace, which issues SearchWorkspace with a query carrying no ResourcePolicyQuery, and PrepareResourcePolicyQuery returns the query unmodified when that field is nil, so the workspace service applies no policy filter. The workspace UUID is not secret, because the unauthenticated public page served for a share link embeds it as START_REPOSITORY. Any account holding a standard user role can therefore submit the UUID and receive the link hash and URL, the owner's user identifier, the hidden share user login, the permission set, the download limit and count, the target users, the expiry, and the password-required flag, while a direct read of the shared node from the same account is refused.

CVSS v4.0

Score 5.3medium

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
Low
User Interaction
None
Vuln. Confidentiality
Low
Vuln. Integrity
None
Vuln. Availability
None
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Affected software

pydio

cells

Affected versions
>=5.0.0 <=5.0.2
GitHub Actionsmore threats →cve
cells
pkg:github/cells
Affected versions
>=5.0.0 <=5.0.2

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/25/2026, 02:41:52 UTC

Technical Analysis

CVE-2026-76032 is a missing authorization vulnerability in Pydio Cells 5.0.0 through 5.0.2. The REST endpoint GET /a/share/link/{Uuid} returns share-link details to any authenticated user without performing authorization checks. The handler reads the workspace UUID from the path and calls LinkById, but does not verify if the requesting user has permission to access the share link. The workspace UUID is publicly exposed in unauthenticated share pages, allowing any authenticated user with a standard role to retrieve sensitive share-link metadata. Other related handlers enforce resource policy checks and return not-found errors to avoid disclosing existence, but this handler does not. The vulnerability allows unauthorized disclosure of share-link metadata, although direct access to the shared node is still restricted.

Potential Impact

An authenticated user with a standard role can retrieve sensitive metadata about share links they are not authorized to access. This includes the share link hash and URL, the owner's user identifier, hidden share user login, permission sets, download limits and counts, target users, expiry times, and whether a password is required. While direct access to the shared content is still denied, this information disclosure could aid attackers in further reconnaissance or targeted attacks against shared resources.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict authenticated user roles to limit exposure and monitor access to share-link endpoints. Avoid sharing workspace UUIDs publicly if possible. Follow vendor guidance once an official fix or update is released for Pydio Cells versions 5.0.0 through 5.0.2.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
VulnCheck
Date Reserved
2026-08-18T19:28:30.086Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 6a84baf8c6e8be0332afda62

Added to database: 08/18/2026, 20:05:12 UTC

Last enriched: 09/25/2026, 02:41:52 UTC

Last updated: 10/02/2026, 02:46:06 UTC

Views: 72

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses