Description
Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains a server-side request forgery and missing authorization vulnerability in the OnlyOffice save callback editUploadOfficeFileById. Unauthenticated attackers can supply arbitrary url and key parameters to make the server fetch internal URLs and overwrite any user's stored file, then read results via queryFileToShowById.
Published: 2026-10-08
Score: 9.1 Critical
EPSS: n/a
KEV: No
Impact: Remote File Write/Overwrite via unauthenticated SSRF
Action: Immediate Patch
AI Analysis

Impact

Dromara Skyeye contains a server‑side request forgery that allows an attacker to supply arbitrary URL and key parameters to the editUploadOfficeFileById endpoint. Unauthenticated users can force the server to request internal addresses and overwrite any stored file belonging to any user. The overwrite can then be read via queryFileToShowById, enabling an attacker to place malicious content or gain further foothold into the system. This flaw is a classic case of insecure input handling (CWE‑918) and results in a loss of file integrity and confidentiality, and potentially a full compromise of the compromised user’s data.

Affected Systems

The vulnerability affects the Dromara Skyeye platform. No specific version range is listed in the CNA data, so any deployment using the code prior to commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 may be vulnerable. Administrators should verify the exact build they are running and consult the project’s GitHub repository for the latest patch status.

Risk and Exploitability

The CVSS score of 9.1 indicates a high impact and relatively easy exploitation. The EPSS score is not available, and the CVE is not listed in the CISA KEV catalog. The most likely attack vector is via unauthenticated remote network access to the Skyeye web service; the attacker can trigger the SSRF directly by submitting crafted requests. Although the vulnerability is not tied to an existing exploit, the high severity and the nature of the flaw mean that it should be treated as a high priority risk.

Generated by OpenCVE AI on October 8, 2026 at 21:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest release of Skyeye that addresses the editUploadOfficeFileById flaw or revert to a pre‑commit state before 003549ae5615bd114ba5bb8ddf6a8e8ead97c321.
  • Restrict access to the editUploadOfficeFileById endpoint so that only authenticated and authorized users can invoke it, or remove the endpoint entirely if it is not needed.
  • Configure outbound request filtering or network segmentation to block the application from resolving or requesting internal URLs, and enforce a strict allowlist for any outbound traffic from the Skyeye service.

Generated by OpenCVE AI on October 8, 2026 at 21:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Description Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains a server-side request forgery and missing authorization vulnerability in the OnlyOffice save callback editUploadOfficeFileById. Unauthenticated attackers can supply arbitrary url and key parameters to make the server fetch internal URLs and overwrite any user's stored file, then read results via queryFileToShowById.
Title Dromara Skyeye Unauthenticated SSRF and File Overwrite via editUploadOfficeFileById
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 9.1, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-08T20:15:56.039Z

Reserved: 2026-10-08T20:02:31.075Z

Link: CVE-2026-107781

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-08T21:17:53.080

Modified: 2026-10-08T21:27:15.010

Link: CVE-2026-107781

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T21:30:18Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)