OVERVIEW: CVE-2026-6569 is an authentication bypass vulnerability affecting KodCloud KodExplorer versions up to 4.52. The flaw exists in the fileGet endpoint located at /app/controller/share.class.php, where improper handling of the fileUrl parameter allows attackers to circumvent authentication controls. SEVERITY: This vulnerability carries a CVSS score of 7.3 (HIGH) with a network-based attack vector requiring no authentication or user interaction. The attack has low complexity and impacts confidentiality, integrity, and availability equally. The moderate FAUCET risk score of 47.0/100 reflects the vulnerability's exploitability and potential impact. EXPLOITATION STATUS: There is no evidence of active exploitation at this time. The vulnerability does not appear on the Known Exploited Vulnerabilities (KEV) catalog and is classified as inactive on threat tracking lists. The EPSS score of 0.0008 indicates minimal probability of exploitation in the wild, suggesting this remains primarily a theoretical risk requiring patching during normal maintenance cycles.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Kodcloud | KodExplorer | 4.0, 4.1, 4.10, 4.11, 4.12, 4.13, 4.14, 4.15, 4.16, 4.17, 4.18, 4.19, 4.2, 4.20, 4.21, 4.22, 4.23, 4.24, 4.25, 4.26, 4.27, 4.28, 4.29, 4.3, 4.30, 4.31, 4.32, 4.33, 4.34, 4.35, 4.36, 4.37, 4.38, 4.39, 4.4, 4.40, 4.41, 4.42, 4.43, 4.44, 4.45, 4.46, 4.47, 4.48, 4.49, 4.5, 4.50, 4.51, 4.52, 4.6, 4.7, 4.8, 4.9CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.