CVE-2026-76032: Missing Authorization in pydio cells
Pydio Cells 5.0.0 through 5.0.2 returns share-link details to any authenticated user. The REST handler for GET /a/share/link/{Uuid} in idm/share/rest/handler.go reads the workspace UUID from the path, calls LinkById, and writes the result with no authorization step, whereas the sibling handler for GET /a/share/cell/{Uuid} loads the workspace and requires MatchPolicies with ResourcePolicyAction_READ, returning a not-found error so that existence is not disclosed. Nothing compensates further down: GetLinkWorkspace reaches GetOrCreateWorkspace, which issues SearchWorkspace with a query carrying no ResourcePolicyQuery, and PrepareResourcePolicyQuery returns the query unmodified when that field is nil, so the workspace service applies no policy filter. The workspace UUID is not secret, because the unauthenticated public page served for a share link embeds it as START_REPOSITORY. Any account holding a standard user role can therefore submit the UUID and receive the link hash and URL, the owner's user identifier, the hidden share user login, the permission set, the download limit and count, the target users, the expiry, and the password-required flag, while a direct read of the shared node from the same account is refused.
AI Analysis
Technical Summary
CVE-2026-76032 is a missing authorization vulnerability in Pydio Cells 5.0.0 through 5.0.2. The REST endpoint GET /a/share/link/{Uuid} returns share-link details to any authenticated user without performing authorization checks. The handler reads the workspace UUID from the path and calls LinkById, but does not verify if the requesting user has permission to access the share link. The workspace UUID is publicly exposed in unauthenticated share pages, allowing any authenticated user with a standard role to retrieve sensitive share-link metadata. Other related handlers enforce resource policy checks and return not-found errors to avoid disclosing existence, but this handler does not. The vulnerability allows unauthorized disclosure of share-link metadata, although direct access to the shared node is still restricted.
Potential Impact
An authenticated user with a standard role can retrieve sensitive metadata about share links they are not authorized to access. This includes the share link hash and URL, the owner's user identifier, hidden share user login, permission sets, download limits and counts, target users, expiry times, and whether a password is required. While direct access to the shared content is still denied, this information disclosure could aid attackers in further reconnaissance or targeted attacks against shared resources.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict authenticated user roles to limit exposure and monitor access to share-link endpoints. Avoid sharing workspace UUIDs publicly if possible. Follow vendor guidance once an official fix or update is released for Pydio Cells versions 5.0.0 through 5.0.2.
CVE-2026-76032: Missing Authorization in pydio cells
Description
Pydio Cells 5.0.0 through 5.0.2 returns share-link details to any authenticated user. The REST handler for GET /a/share/link/{Uuid} in idm/share/rest/handler.go reads the workspace UUID from the path, calls LinkById, and writes the result with no authorization step, whereas the sibling handler for GET /a/share/cell/{Uuid} loads the workspace and requires MatchPolicies with ResourcePolicyAction_READ, returning a not-found error so that existence is not disclosed. Nothing compensates further down: GetLinkWorkspace reaches GetOrCreateWorkspace, which issues SearchWorkspace with a query carrying no ResourcePolicyQuery, and PrepareResourcePolicyQuery returns the query unmodified when that field is nil, so the workspace service applies no policy filter. The workspace UUID is not secret, because the unauthenticated public page served for a share link embeds it as START_REPOSITORY. Any account holding a standard user role can therefore submit the UUID and receive the link hash and URL, the owner's user identifier, the hidden share user login, the permission set, the download limit and count, the target users, the expiry, and the password-required flag, while a direct read of the shared node from the same account is refused.
CVSS v4.0
Score 5.3medium
Affected software
pydio
cells
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-76032 is a missing authorization vulnerability in Pydio Cells 5.0.0 through 5.0.2. The REST endpoint GET /a/share/link/{Uuid} returns share-link details to any authenticated user without performing authorization checks. The handler reads the workspace UUID from the path and calls LinkById, but does not verify if the requesting user has permission to access the share link. The workspace UUID is publicly exposed in unauthenticated share pages, allowing any authenticated user with a standard role to retrieve sensitive share-link metadata. Other related handlers enforce resource policy checks and return not-found errors to avoid disclosing existence, but this handler does not. The vulnerability allows unauthorized disclosure of share-link metadata, although direct access to the shared node is still restricted.
Potential Impact
An authenticated user with a standard role can retrieve sensitive metadata about share links they are not authorized to access. This includes the share link hash and URL, the owner's user identifier, hidden share user login, permission sets, download limits and counts, target users, expiry times, and whether a password is required. While direct access to the shared content is still denied, this information disclosure could aid attackers in further reconnaissance or targeted attacks against shared resources.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict authenticated user roles to limit exposure and monitor access to share-link endpoints. Avoid sharing workspace UUIDs publicly if possible. Follow vendor guidance once an official fix or update is released for Pydio Cells versions 5.0.0 through 5.0.2.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-08-18T19:28:30.086Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a84baf8c6e8be0332afda62
Added to database: 08/18/2026, 20:05:12 UTC
Last enriched: 09/25/2026, 02:41:52 UTC
Last updated: 10/02/2026, 02:46:06 UTC
Views: 72
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.