V4: Cloudreve WOPI view sessions can write files and WOPI access token secret is ignored (CVE-2026-62323)
Cloudreve v4's WOPI integration has a vulnerability where access tokens are improperly validated. The token format includes a session ID and a random secret suffix, but the system only validates the session ID prefix and ignores the secret suffix. Additionally, viewer sessions created for view-only actions can still perform write operations if the underlying file permissions allow it. This flaw allows an attacker with a valid session ID to forge tokens and write to files they should only be able to view.
AI Analysis
Technical Summary
Cloudreve's WOPI integration generates access tokens composed of a session ID and a 128-character random secret suffix. However, the middleware responsible for validating these tokens only verifies the session ID prefix and does not compare the full token against the stored secret. Consequently, any token suffix is accepted for a valid session ID. Furthermore, the WOPI viewer session does not enforce the requested viewer action (view vs. edit), allowing sessions created for viewing to invoke write endpoints if the file system permissions permit. This vulnerability was confirmed on Cloudreve v4.16.1 and the latest master commit. Exploitation allows an attacker with knowledge of a valid session ID to read and write files without proper authorization.
Potential Impact
An attacker who obtains or guesses a valid WOPI session ID can bypass the intended access token protection and perform unauthorized file modifications through the WOPI write API endpoints. This breaks the expected access control model where view-only sessions should not have write capabilities. The vulnerability affects deployments using WOPI viewers for user files and can lead to unauthorized data tampering. The impact is limited to users with at least some privileges to create WOPI sessions and depends on file system write permissions.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict access to WOPI session IDs and URLs to trusted parties only. Monitor for suspicious WOPI write activity and consider disabling WOPI write endpoints if not required. Review file permissions to minimize writable files accessible via WOPI. Follow official Cloudreve advisories for updates and patches addressing this vulnerability.
V4: Cloudreve WOPI view sessions can write files and WOPI access token secret is ignored (CVE-2026-62323)
Description
Cloudreve v4's WOPI integration has a vulnerability where access tokens are improperly validated. The token format includes a session ID and a random secret suffix, but the system only validates the session ID prefix and ignores the secret suffix. Additionally, viewer sessions created for view-only actions can still perform write operations if the underlying file permissions allow it. This flaw allows an attacker with a valid session ID to forge tokens and write to files they should only be able to view.
CVSS v3.1
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Cloudreve's WOPI integration generates access tokens composed of a session ID and a 128-character random secret suffix. However, the middleware responsible for validating these tokens only verifies the session ID prefix and does not compare the full token against the stored secret. Consequently, any token suffix is accepted for a valid session ID. Furthermore, the WOPI viewer session does not enforce the requested viewer action (view vs. edit), allowing sessions created for viewing to invoke write endpoints if the file system permissions permit. This vulnerability was confirmed on Cloudreve v4.16.1 and the latest master commit. Exploitation allows an attacker with knowledge of a valid session ID to read and write files without proper authorization.
Potential Impact
An attacker who obtains or guesses a valid WOPI session ID can bypass the intended access token protection and perform unauthorized file modifications through the WOPI write API endpoints. This breaks the expected access control model where view-only sessions should not have write capabilities. The vulnerability affects deployments using WOPI viewers for user files and can lead to unauthorized data tampering. The impact is limited to users with at least some privileges to create WOPI sessions and depends on file system write permissions.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict access to WOPI session IDs and URLs to trusted parties only. Monitor for suspicious WOPI write activity and consider disabling WOPI write endpoints if not required. Review file permissions to minimize writable files accessible via WOPI. Follow official Cloudreve advisories for updates and patches addressing this vulnerability.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-c3jm-gv5r-9wcp
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-62323"]
- Ecosystems
- ["Go"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6a65422e9c2644c7f808a5fc
Added to database: 07/25/2026, 23:09:34 UTC
Last enriched: 07/25/2026, 23:56:48 UTC
Last updated: 07/26/2026, 01:19:47 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.