Auditing file-serving permission checks, using CVE-2026-100727 as the model
Auditing file-serving permission checks, using CVE-2026-100727 as the model Why this audit is worth running CVE-2026-100727 affects GROWI versions before v7.5.5 and allows a remote unauthenticated attacker to read files contained in non-public pages when the file upload setting is configured as "Local". The advisory JVN#24352487 classifies it as CWE-552 and scores it 6.9 on CVSS 4.0 and 5.3 on…
The CVE-2026-100727 vulnerability affects GROWI versions prior to v7.5.5 and allows unauthorized remote access to files in non-public pages when the file upload setting is set to Local. This issue is classified under CWE-552 and has a severity rating of 6.9 on CVSS 4.0 and 5.3 on CVSS 3.0. The vendor released a patch in version 7.5.5 on October 5, 2026, following a coordinated disclosure via JPCERT/CC.
The root cause of the problem is that GROWI applies a weak permission check to the stored file referenced by a page, rather than to the page itself. To remediate this issue, users should upgrade to GROWI v7.5.5 and conduct a review of all routes returning file-like content, ensuring that the gating decision and object being accessed align with the user interface's protection.
Testing for this vulnerability is relatively straightforward and should be performed after any upgrade that modifies file handling.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.