CVE-2026-81182 PUBLISHED

SysReptor: Unauthorized file disclosure by broken access control in writable shared notes

Assigner: GitHub_M
Reserved: 26.08.2026 Published: 18.09.2026 Updated: 18.09.2026

SysReptor is a fully customizable pentest reporting platform. Prior to 2026.68, an unauthenticated attacker who holds a public read-write note share link can disclose an uploaded file or image from the same project by updating the shared note to reference the target asset filename. The user-controlled reference causes the shared-note authorization logic to treat the asset as permitted, after which the attacker can download it. The attacker must know the asset filename, and the issue does not permit cross-project access. This issue is fixed in version 2026.68.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
CVSS Score: 4.2

Product Status

Vendor Syslifters
Product sysreptor
Versions
  • Version < 2026.68 is affected

References

Problem Types

  • CWE-639: Authorization Bypass Through User-Controlled Key CWE