S4E just found a high top 10 tcp port service scan
high·Web Vulnerabilities·Updated Aug 14, 2026

CVE-2026-25231 Scanner

CVE-2026-25231 Scanner - Arbitrary File Read vulnerability in FileRise

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsdomain, subdomain, ipv4
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-25231
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

FileRise is a self-hosted web file manager / WebDAV server. Versions prior to 3.3.0, the application contains an unauthenticated file read vulnerability due to the lack of access control on the /uploads directory. Files uploaded to this directory can be accessed directly by any user who knows or can guess the file path, without requiring authentication. As a result, sensitive data could be exposed, and privacy may be breached. This vulnerability is fixed in 3.3.0.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
FileRiseby error311
< 3.3.0
Updated Aug 19, 2026View on NVD →
Detail

FileRise is a file management software used by individuals and businesses to upload and share files securely. It is typically implemented in web servers where file upload functionalities are required for various professional and non-professional purposes. Its ease of use and effectiveness makes it a popular choice among web administrators and developers. It allows users to manage their file uploads and sharing, which is essential for collaborative work environments. FileRise supports various file formats and is designed to be scalable according to usage needs. The software's flexibility and user-friendly interface contribute to its widespread adoption.

The Arbitrary File Read vulnerability identified in FileRise occurs due to the insufficient access control over the /uploads directory. This oversight allows unauthenticated attackers to access files uploaded to the directory without proper permissions. The vulnerability is classified as high severity due to the potential exposure of sensitive files, which can lead to data leakage and compromise of privacy. Attackers exploiting this flaw can easily read files if the file paths are known or can be guessed. Such vulnerabilities jeopardize the confidentiality of sensitive information. Being aware of file paths or correctly guessing them may lead to successful exploitation.

The vulnerability primarily targets the /uploads directory where files are stored, allowing unauthorized reading of these files. Attack vectors include directing HTTP GET requests towards the directory or specific files within it. The vulnerability is present when the raw HTTP request to '/uploads/README.md' returns a successful 200 status code and the content is not in HTML format, indicating access to non-webpage data. Additionally, an HTTP GET request that results in a 301 redirect status can further expose the /uploads/ path to attackers. This lack of proper authorization checks at critical endpoints is the technical root cause behind the vulnerability.

When exploited, this vulnerability allows malicious users to access sensitive data stored in files within the FileRise /uploads folder. Such unauthorized data access can lead to privacy breaches, exposure of confidential information, and potential data manipulation. The impact is particularly severe for systems hosting confidential or personal information, where data exposure could lead to legal implications and damage to reputation. Organizations using vulnerable versions may face privacy complaints or regulatory penalties due to improper data handling protocols. Therefore, mitigating this vulnerability is crucial to maintaining data integrity and privacy.

REFERENCES

Solution Advice
  • Upgrade to FileRise version 3.3.0 or later to ensure the unauthenticated file read vulnerability is patched.
  • Implement stringent access control policies on directories containing sensitive files to prevent unauthorized access.
  • Regularly audit file permissions and access logs to detect and mitigate unauthorized access attempts promptly.
  • Educate personnel managing FileRise instances on secure configuration practices to minimize human error in setting access controls.
  • Use firewall rules or intrusion detection systems to detect anomalies in access patterns that may indicate exploitation attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.