Collabora KodExplorer Improper Authorization Vulnerability in File Upload Endpoint

Vulnerability

A business logic bypass vulnerability has been identified in Collabora KodExplorer versions through 4.52. The issue resides in the file '/app/controller/share.class.php', specifically within the file upload endpoint. This vulnerability allows for improper authorization, enabling remote exploitation. Even when upload permissions are disabled for a shared folder, the application fails to enforce this restriction, allowing unauthorized file uploads into the shared directory.

Impact

Exploitation of this vulnerability could lead to unauthorized file uploads, potentially allowing for the injection of malicious content, phishing files, or tampering with collaboratively shared data.

Reproduction

To reproduce this vulnerability, share a folder and disable upload permissions using the 'canUpload' setting. Then, access the share link and use it to upload files through the 'share/fileUpload' endpoint. This can be done without authentication, bypassing the intended restriction on uploads.

Added: Apr 19, 2026, 1:19 PM
Updated: Apr 19, 2026, 1:19 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
8.2
remediation
0.0
relevance
6.0
threat
6.4
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.