{"id":"CVE-2026-54560","summary":"Cloudreve: OAuth access tokens bypass scope enforcement due to missing client_id claim","details":"Cloudreve is a self-hosted file management and sharing system. From 4.12.0 until 4.16.1, Cloudreve's OAuth access tokens are issued without the OAuth client_id claim, so the JWT verifier does not load token scopes into request context and RequiredScopes treats the request like non-scoped session authentication, allowing a low-scope OAuth access token to call APIs requiring higher scopes such as file, share, workflow, user setting, WebDAV account, and potentially admin scopes. This issue is fixed in version 4.16.1.","aliases":["GHSA-vgj4-345g-jcf8"],"modified":"2026-07-17T03:47:38.826324665Z","published":"2026-07-15T14:40:24.765Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-863"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54560.json"},"references":[{"type":"WEB","url":"https://github.com/cloudreve/cloudreve/releases/tag/4.16.1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54560.json"},{"type":"ADVISORY","url":"https://github.com/cloudreve/cloudreve/security/advisories/GHSA-vgj4-345g-jcf8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54560"},{"type":"FIX","url":"https://github.com/cloudreve/cloudreve/commit/ed20843dc3df20a25fcaf6b538647e11c4d68d87"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/cloudreve/cloudreve","events":[{"introduced":"87d48ac4a7acbc68064c2b9cb23793ac97f4392d"},{"fixed":"ed20843dc3df20a25fcaf6b538647e11c4d68d87"},{"fixed":"26b6b1044b0253c5ead7d5a90eaa10ff67ac2582"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"4.12.0"},{"fixed":"4.16.1"}]}}],"versions":["4.16.0","4.15.0","4.14.1","4.14.0","4.13.0","4.12.1","4.12.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54560.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L"}]}