Vulnerability Description
Seahub before 13.0.23 does not enforce SHARE_LINK_LOGIN_REQUIRED on GET /api/v2.1/share-link-zip-task/, allowing unauthenticated users to bypass authentication. Attackers with a folder share-link token can call the GET endpoint to obtain a fileserver zip token and download entire shared directory trees.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/haiwen/seahub/commit/162cddae0831188d02bb8d451dc2193e197dcc57
- https://github.com/haiwen/seahub/commit/b609949cf64ed6a15708d0fb5ea9c179962e23cc
- https://github.com/haiwen/seahub/issues/9050
- https://plus.seafile.com/wiki/publish/seafile-wiki/v5D5/
- https://www.vulncheck.com/advisories/seahub-authentication-bypass-in-sharelinkzi
FAQ
What is CVE-2026-56768?
CVE-2026-56768 is a vulnerability with a CVSS score of 8.8 (HIGH). Seahub before 13.0.23 does not enforce SHARE_LINK_LOGIN_REQUIRED on GET /api/v2.1/share-link-zip-task/, allowing unauthenticated users to bypass authentication. Attackers with a folder share-link toke...
How severe is CVE-2026-56768?
CVE-2026-56768 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-56768?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.