Junglewise Threat Intelligence

CVE-2026-6105: perfree go-fastdfs-web improper authorization in doInstall interface

CVE-2026-6105 · Severity: high · CVSS 7.3 · Published 2026-04-11

Vendors: Perfree.

Executive brief

A security vulnerability exists in go-fastdfs-web, a web-based management interface for the go-fastdfs distributed file system. The application fails to disable or protect its installation interface after the initial setup is complete. This allows a remote attacker to re-run the installation process, create a new administrative account, and take full control of the platform, potentially leading to the theft or deletion of stored files and exposure of server information.

Technical details

An improper authorization vulnerability exists in perfree go-fastdfs-web versions up to 1.3.7 within the `doInstall` interface of `InstallController.java`. The root cause is that the application does not remove or restrict access to the installation routes (`/install/doInstall`) after the initial setup is finished. A remote, unauthenticated attacker can send a crafted POST request to this endpoint to perform a 'second installation,' allowing them to register a new administrative user. Once authenticated with this new account, the attacker can access system information, manage server configurations, and upload or delete files. As of the advisory date, the vendor has not responded to disclosure attempts.

Affected products

  • perfree go-fastdfs-web up to 1.3.7

Timeline

  • 2026-03-17: disclosed: Vulnerability details and PoC shared on Gitee
  • 2026-04-11: advisory: CVE-2026-6105 published

References