CVE-2026-33330 details a broken access control vulnerability in FileRise versions prior to 3.10.0, specifically within its ONLYOFFICE integration. This flaw allows an authenticated user with read-only privileges to overwrite files with attacker-controlled content by forging ONLYOFFICE save callbacks. Rated 7.1 HIGH (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N), it presents a network-based attack with low complexity and high integrity impact. There is no evidence of active exploitation, public exploit code, or significant community attention, and it is not included in CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.10.0CPE matchmatch criteria | cpe:2.3:a:filerise:filerise:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.