Urgent.News

What's breaking now, across thousands of outlets.

More in Tech

CVE-2026-100727: unauthenticated file read in GROWI's local upload mode

CVE-2026-100727: unauthenticated file read in GROWI's local upload mode GROWI, the wiki and collaboration platform published by GROWI, Inc., received a security fix in version 7.5.5 on October 5…

  • GROWI releases version 7.5.5 to fix CVE-2026-100727 vulnerability.
  • Unauthenticated attacker can read local files via unpatched GROWI installations.
  • Upgrading to 7.5.5 or using external storage mitigates confidentiality risk.

More from Friday 9 October →