CVE-2026-92616 Overview
CVE-2026-92616 is a privilege escalation vulnerability in FileRise versions prior to 3.28.0. The flaw stems from improper session isolation between the WebDAV interface and the web application session context. Authenticated low-privilege attackers can combine valid Basic-Auth credentials with an active admin PHPSESSID cookie to bypass authorization boundaries. The WebDAV layer inherits elevated privileges from an ambient web session instead of enforcing independent stateless authentication as required by RFC 4918. Successful exploitation grants unauthorized read and write access to files controlled by higher-privileged accounts.
Critical Impact
Authenticated low-privilege users can escalate to administrator-level file access on the FileRise WebDAV endpoint, compromising confidentiality and integrity of stored data.
Affected Products
- FileRise versions prior to 3.28.0
- FileRise WebDAV interface
- FileRise web application session handler
Discovery Timeline
- 2026-09-16 - CVE-2026-92616 published to NVD
- 2026-09-16 - Last updated in NVD database
Technical Details for CVE-2026-92616
Vulnerability Analysis
The vulnerability resides in how FileRise handles authentication across two distinct access channels. The WebDAV interface should authenticate every request statelessly using HTTP Basic-Auth, as defined by RFC 4918. FileRise instead consults the shared PHP session store when processing WebDAV requests. When an attacker submits a WebDAV request with valid low-privilege Basic-Auth credentials and attaches an admin PHPSESSID cookie belonging to an active elevated session, the WebDAV layer honors the session context. The result is a privilege confusion where the WebDAV authorization decision is derived from an ambient browser session rather than from the credentials transmitted on the request. This falls under CWE-613: Insufficient Session Expiration and represents a broken access control pattern.
Root Cause
The root cause is the WebDAV handler's dependency on the web application's session state. Stateless protocols must not inherit trust from concurrent stateful sessions. FileRise conflated the two authentication surfaces, letting a valid PHPSESSID override the identity asserted in the Authorization header.
Attack Vector
Exploitation requires network access to the FileRise application, valid low-privilege Basic-Auth credentials, and possession of an admin PHPSESSID cookie. The attacker issues WebDAV requests such as PROPFIND, GET, PUT, or DELETE against the WebDAV endpoint. The requests include both the low-privilege Basic-Auth header and the admin session cookie. FileRise resolves the request under administrator privileges and returns or modifies files outside the attacker's authorized scope.
No verified exploit code has been published. See the VulnCheck FileRise Privilege Escalation Advisory for the technical write-up.
Detection Methods for CVE-2026-92616
Indicators of Compromise
- WebDAV requests (PROPFIND, PUT, MOVE, DELETE) that include both an Authorization: Basic header and a PHPSESSID cookie from a different user context.
- Access log entries showing low-privilege accounts performing WebDAV operations on files or directories restricted to administrators.
- Unexpected file creation, modification, or deletion patterns originating from the WebDAV endpoint outside normal user working sets.
Detection Strategies
- Correlate the authenticated Basic-Auth user with the session identity behind each WebDAV request and alert when they diverge.
- Baseline WebDAV method usage per account and flag deviations such as low-privilege users issuing bulk PROPFIND or write operations.
- Inspect reverse-proxy or web server logs for concurrent use of the same PHPSESSID across multiple source IPs.
Monitoring Recommendations
- Enable verbose WebDAV request logging including the resolved principal and cookie header presence.
- Forward FileRise access logs into a centralized analytics platform for cross-session correlation and long-term retention.
- Monitor for administrator-level file changes attributed to session cookies rather than direct administrator authentication.
How to Mitigate CVE-2026-92616
Immediate Actions Required
- Upgrade FileRise to version 3.28.0 or later, which enforces stateless authentication on the WebDAV interface.
- Invalidate all active administrator sessions and rotate credentials for any account whose PHPSESSID may have been exposed.
- Restrict WebDAV endpoint access to trusted networks or VPN clients until the patch is deployed.
- Audit file activity logs for the WebDAV path to identify unauthorized reads or writes performed under an inherited admin session.
Patch Information
The fix is included in FileRise v3.28.0. Release notes and downloads are available at the GitHub FileRise Release v3.28.0 page. The update decouples WebDAV authentication from the web application session store and enforces per-request Basic-Auth evaluation per RFC 4918.
Workarounds
- Disable the WebDAV interface at the web server or reverse proxy layer if the feature is not required.
- Configure the web server to strip cookies from requests targeting the WebDAV endpoint, forcing authentication to fall back to Basic-Auth.
- Enforce short session lifetimes and terminate administrator sessions immediately after use to reduce the window of session inheritance.
# Example: strip cookies from WebDAV requests at an nginx reverse proxy
location /webdav/ {
proxy_set_header Cookie "";
proxy_pass http://filerise_backend;
}
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.