OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-77633

HIGH · CVSS 7.1 EPSS 0.37% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-22 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

The vulnerability affects Cloudreve, a self-hosted file management system, where an authenticated user with Files.Write permission can exploit a flaw in the PrepareUpload function to bypass storage quotas. This allows users to reserve more storage than permitted, potentially exhausting host storage and denying upload capabilities to other users. Organizations using versions prior to 4.18.0 should prioritize updating to mitigate the risk of storage exhaustion and service disruption.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-77633
Severity
HIGH
CVSS
7.1
EPSS
0.37%

Original NVD Description

Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, PrepareUpload in pkg/filemanager/fs/dbfs/upload.go checks a stale in-memory user storage value through validateUserCapacity and later applies an unconditional storage charge outside the same quota-enforcing transaction. An authenticated user with Files.Write permission can issue concurrent upload-session requests that read the same capacity snapshot, all pass the MaxStorage check, and reserve their declared sizes through CommitWithStorageDiff. The resulting reservations can exceed the account quota and can be materialized as chunked uploads that exhaust host storage and deny uploads to other users. The default local-storage policy and default User group are affected. This issue is fixed in version 4.18.0.