Impact
An authorization bypass flaw exists in the Shirasagi groupware, allowing an attacker to supply a user‑controlled key and bypass normal access checks to retrieve files from the shared file feature. The flaw can be exploited to read confidential data that should otherwise be protected by the application’s authorization logic. The vulnerability falls under CWE‑639, which highlights weaknesses in privilege enforcement.
Affected Systems
The affected product is Shirasagi, a groupware solution offered by the Shirasagi Project. Detailed version information is not provided in the current advisory, so all currently deployed versions may be impacted until a vendor patch is released.
Risk and Exploitability
With a CVSS score of 5.3 the vulnerability is of moderate severity. The exploit probability (EPSS) is not available, and it is not listed in CISA‑KEV, indicating a lower likelihood of widespread exploitation at this time. However, because the flaw permits unauthorized file access, it has the potential to compromise the confidentiality of stored documents if the attacker can supply the malicious key. The attack vector is inferred to be remote or local depending on how the key is provided—most likely remote if an attacker can interact with the application’s file‑sharing interface.
OpenCVE Enrichment