CVE-2026-3266 PUBLISHED

Improper access control vulnerability has been discovered in OpenText™ Filr.

Assigner: OpenText
Reserved: 26.02.2026 Published: 03.03.2026 Updated: 03.03.2026

Missing Authorization vulnerability in OpenText™ Filr allows Authentication Bypass. The vulnerability could allow unauthenticated users to get XSRF token and do RPC with carefully crafted programs.

This issue affects Filr: through 25.1.2.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:H/VA:L/SC:L/SI:L/SA:L/S:P/AU:Y/R:I/V:D/RE:M/U:Red
CVSS Score: 8.3

Product Status

Vendor OpenText™
Product Filr
Versions Default: unaffected
  • affected from 0 to 25.1.2 (incl.)

Solutions

https://portal.microfocus.com/s/article/KM000045579?language=en_US

References

Problem Types

  • CWE-862 Missing Authorization CWE

Impacts

  • CAPEC-115 Authentication Bypass