CVE-2026-92616: Insufficient Session Expiration in error311 FileRise
FileRise before version 3.28.0 contains a privilege escalation vulnerability that allows authenticated low-privilege attackers to gain unauthorized read and write access by exploiting improper session isolation between the WebDAV interface and the web application session context. Attackers can combine valid Basic-Auth credentials with an active admin PHPSESSID cookie to bypass authorization boundaries, as the WebDAV layer incorrectly inherits elevated privileges from an ambient web session rather than enforcing independent stateless authentication per RFC 4918.
AI Analysis
Technical Summary
CVE-2026-92616 describes a privilege escalation vulnerability in FileRise prior to version 3.28.0. The flaw arises from improper session isolation between the WebDAV interface and the web application session context. Specifically, the WebDAV interface incorrectly inherits elevated privileges from an ambient web session (admin PHPSESSID cookie) when combined with valid Basic-Auth credentials, allowing low-privilege authenticated attackers to gain unauthorized read and write access. This violates the expected stateless authentication model defined in RFC 4918 for WebDAV, leading to privilege escalation.
Potential Impact
An authenticated attacker with low privileges can escalate their access rights to gain unauthorized read and write capabilities by exploiting the session isolation flaw. This compromises the integrity and confidentiality of data accessible through the FileRise WebDAV interface. The vulnerability has a high severity rating with a CVSS 4.0 score of 7.6, indicating significant risk if exploited.
Mitigation Recommendations
A fix is available in FileRise version 3.28.0 and later. Users should upgrade to version 3.28.0 or newer to remediate this vulnerability. No additional mitigation steps are indicated beyond applying the official patch.
CVE-2026-92616: Insufficient Session Expiration in error311 FileRise
Description
FileRise before version 3.28.0 contains a privilege escalation vulnerability that allows authenticated low-privilege attackers to gain unauthorized read and write access by exploiting improper session isolation between the WebDAV interface and the web application session context. Attackers can combine valid Basic-Auth credentials with an active admin PHPSESSID cookie to bypass authorization boundaries, as the WebDAV layer incorrectly inherits elevated privileges from an ambient web session rather than enforcing independent stateless authentication per RFC 4918.
CVSS v4.0
Score 7.6high
Affected software
error311
FileRise
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-92616 describes a privilege escalation vulnerability in FileRise prior to version 3.28.0. The flaw arises from improper session isolation between the WebDAV interface and the web application session context. Specifically, the WebDAV interface incorrectly inherits elevated privileges from an ambient web session (admin PHPSESSID cookie) when combined with valid Basic-Auth credentials, allowing low-privilege authenticated attackers to gain unauthorized read and write access. This violates the expected stateless authentication model defined in RFC 4918 for WebDAV, leading to privilege escalation.
Potential Impact
An authenticated attacker with low privileges can escalate their access rights to gain unauthorized read and write capabilities by exploiting the session isolation flaw. This compromises the integrity and confidentiality of data accessible through the FileRise WebDAV interface. The vulnerability has a high severity rating with a CVSS 4.0 score of 7.6, indicating significant risk if exploited.
Mitigation Recommendations
A fix is available in FileRise version 3.28.0 and later. Users should upgrade to version 3.28.0 or newer to remediate this vulnerability. No additional mitigation steps are indicated beyond applying the official patch.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-16T14:28:31.857Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6aaaabff55bf5e2cf5bf8d53
Added to database: 09/16/2026, 14:47:27 UTC
Last enriched: 09/16/2026, 15:01:36 UTC
Last updated: 09/17/2026, 03:09:05 UTC
Views: 11
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.