{"id":"CVE-2026-81182","summary":"SysReptor: Unauthorized file disclosure by broken access control in writable shared notes","details":"SysReptor is a fully customizable pentest reporting platform. Prior to 2026.68, an unauthenticated attacker who holds a public read-write note share link can disclose an uploaded file or image from the same project by updating the shared note to reference the target asset filename. The user-controlled reference causes the shared-note authorization logic to treat the asset as permitted, after which the attacker can download it. The attacker must know the asset filename, and the issue does not permit cross-project access. This issue is fixed in version 2026.68.","aliases":["GHSA-x3m3-v8pv-442r"],"modified":"2026-09-20T11:47:27.210229487Z","published":"2026-09-18T17:48:05.575Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/81xxx/CVE-2026-81182.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-639"]},"references":[{"type":"WEB","url":"https://github.com/Syslifters/sysreptor/releases/tag/2026.68"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/81xxx/CVE-2026-81182.json"},{"type":"ADVISORY","url":"https://github.com/Syslifters/sysreptor/security/advisories/GHSA-x3m3-v8pv-442r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-81182"},{"type":"FIX","url":"https://github.com/Syslifters/sysreptor/commit/1b721e291ebadfc1457bc8d01f7c70fe5da4b035"},{"type":"FIX","url":"https://github.com/Syslifters/sysreptor/commit/1f3fd629c32560fc4280294f8f9bdc44d97c639a"},{"type":"FIX","url":"https://github.com/Syslifters/sysreptor/commit/f730c3acf9ee603f96bb05d598d20f6c4e958eb8"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/syslifters/sysreptor","events":[{"introduced":"0"},{"fixed":"1b721e291ebadfc1457bc8d01f7c70fe5da4b035"},{"fixed":"1f3fd629c32560fc4280294f8f9bdc44d97c639a"},{"fixed":"f730c3acf9ee603f96bb05d598d20f6c4e958eb8"},{"fixed":"03a7c069f98cbbec1010e3f9c459a40681735f85"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"2026.68"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["2026.61","2026.58","2026.55","2026.50","2026.42","2026.36","2026.29","2026.27","2026.25","2026.21","2026.18","2026.12","2026.4","2026.1","2025.110","2025.108","2025.104","2025.102","2025.96","2025.94","2025.90","2025.83","2025.81","2025.80","2025.74","2025.69","2025.64","2025.56","2025.50","2025.43","2025.37","2025.29","2025.25","2025.20","2025.12","2025.4","2024.96","2024.91","2024.81","2024.79","2024.74","2024.70","2024.69","2024.68","2024.63","2024.61","2024.60","2024.58","2024.57","2024.55","2024.49","2024.43","2024.40","2024.30","2024.29","2024.28","2024.20","2024.19","2024.16","2024.13","2024.10","2024.8","2024.3","2024.1","2023.145","2023.142","2023.136","2023.128","2023.122","2023.119","2023.114","0.110","0.102","0.101","0.96","0.95","0.89","0.87","0.83"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-81182.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N"}]}