{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-54560","assignerOrgId":"a0819718-46f1-4df5-94e2-005712e83aaa","state":"PUBLISHED","assignerShortName":"GitHub_M","dateReserved":"2026-06-15T19:04:14.457Z","datePublished":"2026-07-15T14:40:24.765Z","dateUpdated":"2026-07-15T15:16:35.699Z"},"containers":{"cna":{"title":"Cloudreve: OAuth access tokens bypass scope enforcement due to missing client_id claim","problemTypes":[{"descriptions":[{"cweId":"CWE-863","lang":"en","description":"CWE-863: Incorrect Authorization","type":"CWE"}]}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":7.6,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L","version":"3.1"}}],"references":[{"name":"https://github.com/cloudreve/cloudreve/security/advisories/GHSA-vgj4-345g-jcf8","tags":["x_refsource_CONFIRM"],"url":"https://github.com/cloudreve/cloudreve/security/advisories/GHSA-vgj4-345g-jcf8"},{"name":"https://github.com/cloudreve/cloudreve/commit/ed20843dc3df20a25fcaf6b538647e11c4d68d87","tags":["x_refsource_MISC"],"url":"https://github.com/cloudreve/cloudreve/commit/ed20843dc3df20a25fcaf6b538647e11c4d68d87"},{"name":"https://github.com/cloudreve/cloudreve/releases/tag/4.16.1","tags":["x_refsource_MISC"],"url":"https://github.com/cloudreve/cloudreve/releases/tag/4.16.1"}],"affected":[{"vendor":"cloudreve","product":"cloudreve","versions":[{"version":">= 4.12.0, < 4.16.1","status":"affected"}]}],"providerMetadata":{"orgId":"a0819718-46f1-4df5-94e2-005712e83aaa","shortName":"GitHub_M","dateUpdated":"2026-07-15T14:40:24.765Z"},"descriptions":[{"lang":"en","value":"Cloudreve is a self-hosted file management and sharing system. From 4.12.0 until 4.16.1, Cloudreve's OAuth access tokens are issued without the OAuth client_id claim, so the JWT verifier does not load token scopes into request context and RequiredScopes treats the request like non-scoped session authentication, allowing a low-scope OAuth access token to call APIs requiring higher scopes such as file, share, workflow, user setting, WebDAV account, and potentially admin scopes. This issue is fixed in version 4.16.1."}],"source":{"advisory":"GHSA-vgj4-345g-jcf8","discovery":"UNKNOWN"}},"adp":[{"references":[{"url":"https://github.com/cloudreve/cloudreve/security/advisories/GHSA-vgj4-345g-jcf8","tags":["exploit"]}],"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-07-15T15:16:30.603425Z","id":"CVE-2026-54560","options":[{"Exploitation":"poc"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-07-15T15:16:35.699Z"}}]}}