Junglewise Threat Intelligence

CVE-2026-56768: Seafile Seahub authentication bypass in share-link-zip-task endpoint

CVE-2026-56768 · Severity: high · CVSS 8.8 · Published 2026-06-25

Executive brief

Seahub, the web interface for the Seafile file storage platform, contains a security flaw that fails to enforce login requirements for shared folder links. This allows unauthorized individuals who possess a shared folder link to bypass security settings and download the entire contents of that folder. This could lead to the unauthorized exposure of sensitive corporate data and documents stored within the system.

Technical details

A missing authorization vulnerability (CWE-862) exists in Seahub's ShareLinkZipTaskView GET method. The application fails to check the SHARE_LINK_LOGIN_REQUIRED configuration setting when processing requests to the /api/v2.1/share-link-zip-task/ endpoint. An attacker with a valid folder share-link token can exploit this to obtain a fileserver zip token without authenticating, even if the system is configured to require a login for shared links. This allows for the unauthorized recursive download of shared directory structures. The issue is resolved in version 13.0.23.

Affected products

  • Seafile (haiwen) Seahub before 13.0.23

Timeline

  • 2026-05-27: disclosed: Initial security issue reported on GitHub
  • 2026-06-25: advisory: CVE published and NVD record created
  • 2026-06-25: patched: Fix released in version 13.0.23

References