OpenText Filr Authentication Bypass Vulnerability Allowing XSRF Token Theft and RPC Execution

Vulnerability

A missing authorization vulnerability in OpenText Filr, affecting all versions through 25.1.2, allows authentication bypass. This vulnerability could enable unauthenticated users to obtain an XSRF token and perform remote procedure calls (RPC) using carefully crafted programs.

Impact

Exploitation of this vulnerability could lead to unauthorized access and actions being performed on behalf of an authenticated user, by allowing unauthenticated users to obtain XSRF tokens and execute RPCs with them.

Remediation

Users can update to the latest version of Filr (25.4.1), apply the Filr 25.1.3 patch release, or contact OpenText technical support for 24.4 and 23.4 PTFs.

Added: Mar 3, 2026, 11:18 PM
Updated: Mar 3, 2026, 11:18 PM

Vulnerability Rating

Custom Algorithm
spread
0.8
impact
5.0
exploitability
7.4
remediation
7.7
relevance
3.4
threat
0.0
urgency
10.0
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.