Executive brief
A vulnerability in the Cryptobox secure file-sharing platform could allow unauthorized individuals to access shared files. If an attacker obtains a valid sharing link, they can retrieve specific server information that enables them to bypass the link's access code through offline guessing. This could lead to the exposure of sensitive documents intended to be protected by a password or PIN.
Technical details
A vulnerability exists in the external sharing feature of Thales Cryptobox due to improper handling of server-side information related to shared links. An unauthenticated attacker who possesses a valid sharing URL can retrieve metadata or cryptographic material from the server that facilitates an offline brute-force attack against the access code (PIN/password) protecting the share. This bypasses the rate-limiting or account lockout protections typically associated with online authentication attempts. The issue is addressed in Cryptobox version 4.40 hotfix 5 (Helm Chart 4.40.183).
Affected products
- Thales Group Cryptobox 4.37.248 to 4.38.0; fixed in 4.40 hotfix 5 (4.40.183)
Timeline
- 2026-05-07: disclosed
- 2026-05-07: advisory
- 2026-05-11: other: NVD analysis completed