Two high-severity vulnerabilities in the self-hosted web file manager and WebDAV server FileRise exposed organizations to serious compromise. CVE-2026-33072 affects versions before 3.9.0 and stems from a hardcoded default value for PERSISTENT_TOKENS_KEY, which was reused for HMAC token generation, AES configuration encryption, and session-related functions. An unauthenticated attacker could use the shared key to forge upload tokens for arbitrary file uploads to shared folders and decrypt sensitive administrator configuration data, including OIDC client secrets and SMTP passwords.
A second flaw, CVE-2026-33329, affects FileRise versions 1.0.1 through before 3.10.0 and allows path traversal through the resumableIdentifier parameter in the Resumable.js chunked upload handler. An authenticated user with upload permission could write files to arbitrary server directories, trigger recursive deletion of arbitrary directories during cleanup, and use the behavior as a limited file or directory existence oracle. FileRise addressed the issues in versions 3.9.0 and 3.10.0, respectively, underscoring the need for administrators to upgrade promptly and review exposed secrets and file integrity.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-33329 was newly recorded on March 24, 2026, as a FileRise vulnerability involving unsanitized filesystem path construction from resumableIdentifier. The issue was classified under CWE-22 and CWE-73.
FileRise fixed CVE-2026-33329 in version 3.10.0, resolving a path traversal issue in the resumableIdentifier parameter of the Resumable.js upload handler. The flaw affected versions 1.0.1 through before 3.10.0 and could allow arbitrary file write, recursive directory deletion, and limited existence probing by an authenticated uploader.
The vulnerability CVE-2026-33072 was publicly documented as affecting FileRise, with details showing the shared default key was used for HMAC token generation, AES configuration encryption, and session tokens. It was classified under CWE-798 and CWE-1188.
FileRise addressed CVE-2026-33072 in version 3.9.0, fixing a hardcoded default encryption key that could let unauthenticated attackers forge upload tokens and decrypt sensitive configuration secrets. The flaw affected versions prior to 3.9.0.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.