Urgent.News

What's breaking now, across thousands of outlets.

Tech

Auditing file-serving permission checks, using CVE-2026-100727 as the model

Auditing file-serving permission checks, using CVE-2026-100727 as the model Why this audit is worth running CVE-2026-100727 affects GROWI versions before v7.5.5 and allows a remote unauthenticated attacker to read files contained in non-public pages when the file upload setting is configured as "Local". The advisory JVN#24352487 classifies it as CWE-552 and scores it 6.9 on CVSS 4.0 and 5.3 on…

The CVE-2026-100727 vulnerability affects GROWI versions prior to v7.5.5 and allows unauthorized remote access to files in non-public pages when the file upload setting is set to Local. This issue is classified under CWE-552 and has a severity rating of 6.9 on CVSS 4.0 and 5.3 on CVSS 3.0. The vendor released a patch in version 7.5.5 on October 5, 2026, following a coordinated disclosure via JPCERT/CC.

The root cause of the problem is that GROWI applies a weak permission check to the stored file referenced by a page, rather than to the page itself. To remediate this issue, users should upgrade to GROWI v7.5.5 and conduct a review of all routes returning file-like content, ensuring that the gating decision and object being accessed align with the user interface's protection.

Testing for this vulnerability is relatively straightforward and should be performed after any upgrade that modifies file handling.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

How to Test a WordPress Backup Restore (Before You Need It)

Untested backups aren't backups. They're hopes. Here's how to prove yours actually work — the full restore drill I run. What you need A scratch server or local environment (doesn't need to be…

  • Set up testing environment with same PHP version as production
  • Restore database from backup.sql file and verify wpoptions
  • Restore files to web root and update wp-config.php with new DB details

More from Monday 5 October →