<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T22:06:07.420988+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-343222</id>
    <title>EUVD-2026-343222</title>
    <updated>2026-10-06T22:06:07.424636+00:00</updated>
    <content>EUVD-2026-343222</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-343222"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-55502</id>
    <title>fkie_cve-2026-55502</title>
    <updated>2026-10-06T22:06:07.424679+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, POST /api/v4/admin/policy/oauth/signin requires only Admin.Read even though GetOauthRedirectService persists caller-supplied OneDrive secret and app_id values, allowing an OAuth token without Admin.Write to modify storage policy credentials. The route is inside the admin group that requires Admin.Read, but it does not add the local Admin.Write guard used by sibling policy mutation routes. Its handler persists attacker-supplied secret and app_id values into the selected OneDrive storage policy before returning an OAuth URL. This issue is fixed in version 4.17.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-55502"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hq88-5x99-x3gf</id>
    <title>GHSA-hq88-5x99-x3gf — Cloudreve OAuth Admin.Read scope can update OneDrive storage policy credentials</title>
    <updated>2026-10-06T22:06:07.424724+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/cloudreve/Cloudreve/v4, Go: github.com/cloudreve/Cloudreve/v3</p>
<p>## Summary</p>
<p>Cloudreve 4.16.1 has an OAuth scope authorization bypass in the admin storage policy routes. An OAuth bearer token scoped to `Admin.Read` but not `Admin.Write` can call `POST /api/v4/admin/policy/oauth/signin` and update OneDrive storage policy credentials.</p>
<p>The route is inside the admin group that requires `Admin.Read`, but it does not add the local `Admin.Write` guard used by sibling policy mutation routes. Its handler persists attacker-supplied `secret` and `app_id` values into the selected OneDrive storage policy before returning an OAuth URL.</p>
<p>## Impact</p>
<p>An OAuth application that was granted only read-only admin scope can modify persistent storage backend configuration for a OneDrive policy. This can break the storage backend, replace the stored application secret and app ID, and redirect future OAuth setup for that policy to attacker-controlled application parameters. The attack crosses the intended OAuth scope boundary because `Admin.Write` is required for sibling storage policy mutation routes.</p>
<p>## Reproduction</p>
<p>Preconditions:</p>
<p>1. The instance has a OneDrive storage policy.
2. An admin user authorizes an OAuth client for `Admin.Read` but not `Admin.Write`.
3. The OAuth client obtains a bearer access token for that admin user.</p>
<p>Send the following request with that read-only admin scoped token:</p>
<p>```http
POST /api/v4/admin/policy/oauth/signin HTTP/1.1
Authorization: Bearer &lt;admin OAuth token scoped to Admin.Read only&gt;
Content-Type: application/json</p>
<p>{"id":1,…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hq88-5x99-x3gf"/>
  </entry>
</feed>
