Impact
REBUILD is vulnerable to an authorization bypass in the file-editor-save endpoint. By manipulating the url/fileKey argument, an attacker can skip necessary permission checks and save data without proper authorization. This flaw allows unauthorized users to modify or create files remotely, potentially leading to data tampering and exposure of sensitive content. The weakness is classified under CWE-862 and CWE-863.
Affected Systems
The affected product is REBUILD, with any version up to 4.4.11 susceptible to this flaw. The vulnerability resides in the /commons/file-editor-save code path, and the vendor has not released a patch or response. Users should verify whether their deployment uses a version beyond 4.4.11 before assessing impact.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium to high severity level, and the lack of an EPSS rating suggests no consensus on the exploitation probability, but the flaw is publicly disclosed and can be triggered remotely. The absence from the KEV catalog means no known large‑scale attacks have been reported yet, but the missing authorization remains a clear entry point for potential abuse. If unmitigated, an attacker can remotely gain unauthorized write access to files through the affected endpoint.
OpenCVE Enrichment