CVE-2026-82582

Summary

An authorization bypass vulnerability exists in SHIRASAGI through a user-controlled key, which may allow an unauthorized attacker to retrieve files from the groupware's shared file feature.

Affected Software

VendorProductVersion RangeStatus
SHIRASAGI ProjectSHIRASAGI0 <= v1.20.2affected

Weaknesses

  • CWE-639: Authorization bypass through user-controlled key

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References