CVE-2026-100727: unauthenticated file read in GROWI's local upload mode
CVE-2026-100727: unauthenticated file read in GROWI's local upload mode GROWI, the wiki and collaboration platform published by GROWI, Inc., received a security fix in version 7.5.5 on October 5, 2026. The release closes CVE-2026-100727, an access-control defect that lets an unauthenticated visitor read files kept by pages the platform does not expose publicly. The defect applies to deployments…
On October 5, 2026, GROWI, Inc. released version 7.5.5 to address CVE-2026-100727, an unauthenticated file read vulnerability in GROWI's local upload mode. This security flaw allows an unauthorized visitor to access files stored by the platform on the local file system, impacting deployments that store uploads locally. The vulnerability, rated with a base score of 6.9 (CVSS 4.0) and 5.3 (CVSS 3.0), is classified under CWE-552 as files or directories accessible to external parties.
The exploit is possible when GROWI runs a version lower than 7.5.5 and the file upload setting is configured as "Local." The attack involves an unauthenticated attacker requesting files from non-public pages, which the application serves back upon receiving the request. The impact is limited to confidentiality, as the attacker cannot write or execute files or maintain an authenticated session.
To remediate the issue, GROWI users must update to version 7.5.5 and verify that attachment settings are correctly configured after the upgrade. For those unable to upgrade immediately, moving uploads to an external storage backend can mitigate the vulnerability. Following the patch, it is essential to review non-public pages with attached files from the exposure window and rotate any related credentials or tokens.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.