Junglewise Threat Intelligence

CVE-2026-81182: SysReptor unauthorized file disclosure via shared note link

CVE-2026-81182 · Severity: medium · CVSS 4.2 · Published 2026-09-18

Technologies: Syslifters SysReptor. Vendors: Syslifters.

Executive brief

SysReptor is a pentest reporting platform used to document security assessments. An attacker with access to a public read-write note share link can trick the system into granting access to uploaded files or images they shouldn't be able to see by manipulating note content. This allows disclosure of sensitive project files if the attacker knows the target filename.

Technical details

An authorization bypass exists in shared note handling where user-controlled file references in note content are not properly validated before being treated as permitted assets. An unauthenticated attacker holding a public read-write share link can update the note to reference an arbitrary asset filename, causing the authorization logic to incorrectly grant access. The attacker must know the target asset filename and cannot access files outside the shared project. Fixed by making pending_file_ids read-only and tightening file reference detection.

Affected products

  • Syslifters SysReptor before 2026.68

Timeline

  • 2026-09-18: disclosed

References

Related threats